Getting Data In

Does anyone have an easy way to define a serverclass based on the universal forwarder version?

ltrand
Contributor

I was wondering if anyone had a way to easily define a serverclass based on the UF version? We are managing our 5 to 6 upgrade and I'm at a loss on how to get Splunk to automagically determine which app to pick up (because of syntax changes in the inputs.conf) so that all logs are correct. I don't want to hand jam a whitelist obviously, so does anyone have the syntax to do this? Or, is everyone putting both in their inputs.conf for their windows clients & letting splunk figure it all out?

0 Karma
1 Solution

ltrand
Contributor

The resolution to this that we found is as follows:

Put seperate stanza's in the UF 5 & UF 6 language with full settings into the same inputs.conf that go to all windows devices. The UF's will error on the lines that they cannot read due to formatting, but will otherwise process as normal.

After migration is complete then old stanza's can be removed.

View solution in original post

0 Karma

ltrand
Contributor

The resolution to this that we found is as follows:

Put seperate stanza's in the UF 5 & UF 6 language with full settings into the same inputs.conf that go to all windows devices. The UF's will error on the lines that they cannot read due to formatting, but will otherwise process as normal.

After migration is complete then old stanza's can be removed.

0 Karma

jrodman
Splunk Employee
Splunk Employee

Does this have to do with windows-specific inputs like event log, wmi, perfmon, etc?

I don't really have a solution. 😞

0 Karma

ltrand
Contributor

Yes it does, but I can see this as an in general issue as our UF deployment grows larger & we have to rely on more & more disparate groups to keep up with agent upgrades (We have several environments where we can't force down an agent & rely on an on-site admin).

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...