Getting Data In

Does anyone have an easy way to define a serverclass based on the universal forwarder version?

ltrand
Contributor

I was wondering if anyone had a way to easily define a serverclass based on the UF version? We are managing our 5 to 6 upgrade and I'm at a loss on how to get Splunk to automagically determine which app to pick up (because of syntax changes in the inputs.conf) so that all logs are correct. I don't want to hand jam a whitelist obviously, so does anyone have the syntax to do this? Or, is everyone putting both in their inputs.conf for their windows clients & letting splunk figure it all out?

0 Karma
1 Solution

ltrand
Contributor

The resolution to this that we found is as follows:

Put seperate stanza's in the UF 5 & UF 6 language with full settings into the same inputs.conf that go to all windows devices. The UF's will error on the lines that they cannot read due to formatting, but will otherwise process as normal.

After migration is complete then old stanza's can be removed.

View solution in original post

0 Karma

ltrand
Contributor

The resolution to this that we found is as follows:

Put seperate stanza's in the UF 5 & UF 6 language with full settings into the same inputs.conf that go to all windows devices. The UF's will error on the lines that they cannot read due to formatting, but will otherwise process as normal.

After migration is complete then old stanza's can be removed.

0 Karma

jrodman
Splunk Employee
Splunk Employee

Does this have to do with windows-specific inputs like event log, wmi, perfmon, etc?

I don't really have a solution. 😞

0 Karma

ltrand
Contributor

Yes it does, but I can see this as an in general issue as our UF deployment grows larger & we have to rely on more & more disparate groups to keep up with agent upgrades (We have several environments where we can't force down an agent & rely on an on-site admin).

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...