Reporting

How to export forwarder configuration

xabidh
New Member

Hi,

I have installed the forwarder in DC and other server as Indexer.
I do not know how was installed.
I would like to export Forwarder configuration because I have to install a new Forwarder with the same configuration to delete the old one.
What files need to be copied / check?

Thanks in advance.

0 Karma
1 Solution

asimagu
Builder

This is usually configured inside the SplunkForwarder app

$SPLUNK_HOME/etc/apps/SplunkForwarder

but it may be that you configured it in a different way...

View solution in original post

0 Karma

xabidh
New Member

Ok, thanks.

Is necessary change something in the Indexer server?

0 Karma

stmyers7941
Path Finder

The indexer needs to have an inputs.conf with [splunktcp://9997] stanza. You can check to see if your indexer is listening with netstat (assuming nix):
~ $ netstat -tnlp | grep 9997
tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN 24504/splunkd

0 Karma

xabidh
New Member

I already have this sentece in inputs.conf.
I supposed that is not needed in the Indexer point to Forwarder...
I see with the comand "netstat -a" something like that:
TCP [IP of indexer]:9997 [IP of forwarder]:62244

Thanks

0 Karma

vincenteous
Communicator

Hi xabidh,

If you want to implement existing configurations from old forwarder to the new one, I suggest you copy the entirety of $SPLUNK_HOME/etc folder. Copying this folders means you copy all installed apps of old forwarder, inputs.conf, outputs.conf, authentication, and other configurations which has previously been defined on the old one.

0 Karma

asimagu
Builder

This is usually configured inside the SplunkForwarder app

$SPLUNK_HOME/etc/apps/SplunkForwarder

but it may be that you configured it in a different way...

0 Karma

xabidh
New Member

Hi,
I have checked all files inside this folder C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder but I cannot find the file where its configured the indexer. What is the file name where should be contained the IP/name of indexer server?

Regards

0 Karma

MuS
Legend

check any available outputs.conf on your forwarder

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...