Getting Data In

Does anyone have an easy way to define a serverclass based on the universal forwarder version?

ltrand
Contributor

I was wondering if anyone had a way to easily define a serverclass based on the UF version? We are managing our 5 to 6 upgrade and I'm at a loss on how to get Splunk to automagically determine which app to pick up (because of syntax changes in the inputs.conf) so that all logs are correct. I don't want to hand jam a whitelist obviously, so does anyone have the syntax to do this? Or, is everyone putting both in their inputs.conf for their windows clients & letting splunk figure it all out?

0 Karma
1 Solution

ltrand
Contributor

The resolution to this that we found is as follows:

Put seperate stanza's in the UF 5 & UF 6 language with full settings into the same inputs.conf that go to all windows devices. The UF's will error on the lines that they cannot read due to formatting, but will otherwise process as normal.

After migration is complete then old stanza's can be removed.

View solution in original post

0 Karma

ltrand
Contributor

The resolution to this that we found is as follows:

Put seperate stanza's in the UF 5 & UF 6 language with full settings into the same inputs.conf that go to all windows devices. The UF's will error on the lines that they cannot read due to formatting, but will otherwise process as normal.

After migration is complete then old stanza's can be removed.

0 Karma

jrodman
Splunk Employee
Splunk Employee

Does this have to do with windows-specific inputs like event log, wmi, perfmon, etc?

I don't really have a solution. 😞

0 Karma

ltrand
Contributor

Yes it does, but I can see this as an in general issue as our UF deployment grows larger & we have to rely on more & more disparate groups to keep up with agent upgrades (We have several environments where we can't force down an agent & rely on an on-site admin).

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...