Deployment Architecture

Can I migrate to a new Splunk server without re-configuring forwarders?

bayman
Path Finder

I'd like to change my Splunk server to a different Linux distribution from Fedora to Centos. Indexer, search head and splunk web is all running off of one singer server for now. If I give the new Splunk server the same IP as the existing server after shutting down the old server, do I need to do any reconfiguration of all my splunk forwarders?

0 Karma
1 Solution

woodcock
Esteemed Legend

Correct; as long as your new server has the same IP address (or hostname, depending on what you had in your configuration files, e.g. outputs.conf), everything will work just fine. Since you are going back and "getting things right", you should make sure that you setup both a Deployment Server and a Management Console, too.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Correct; as long as your new server has the same IP address (or hostname, depending on what you had in your configuration files, e.g. outputs.conf), everything will work just fine. Since you are going back and "getting things right", you should make sure that you setup both a Deployment Server and a Management Console, too.

0 Karma

adonio
Ultra Champion

are the forwarders outputs.conf is by IP or servername?

0 Karma

bayman
Path Finder

It is by IP

0 Karma

adonio
Ultra Champion

will ask community to verify but i think you will be fine

0 Karma

somesoni2
SplunkTrust
SplunkTrust

I believe they should be fine. Is your standalone instance a Deployment server as well?

0 Karma

bayman
Path Finder

Forwarder management was never configured on this instance. All the apps and forwarders were manually deployed and configured from each host.

0 Karma

somesoni2
SplunkTrust
SplunkTrust

So, as long as new standalone servers is same network configuration (IP, Firewall rule/cname etc if any), this should work just fine.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...