Getting Data In

upgrading from lightweight forwarder to universal forwarder

imacdonald2
Path Finder

Just checking we are planning on upgrading a lightweight forwarder to a universal forwarder.
the plan is
install the universal forwarder
create the /opt/splunkforwarder/old_splunk.seed
Set a deployment server in /opt/splunkforwarder/etc/system/local/deploymentclient.conf
start the universal forwarder.

What I am wondering, will the checkpoint file be honored, if I start the server then wait for the deployment server to send apps the universal forwarder. The app contains the indexes and inputs etc for each of the feeds that the server needs.

Thanks

0 Karma
1 Solution

bmacias84
Champion

Yes, the checkpoint file will be honored, but back up your configs as changes don't occur until restart of splunk. Also verify the $SPLUNK_HOME/var/log/splunk/migration.log, this will tell you which files have been modified. What you are mostly concered about is the fishbucket directory.

Here some additional reading:

Migrating_from_a_light_forwarder

Upgradethenixuniversalforwarder

what-is-this-fishbucket-thing - Found this very informative, but a little out of date.

Hope this helps or gets you started.

View solution in original post

bmacias84
Champion

Yes, the checkpoint file will be honored, but back up your configs as changes don't occur until restart of splunk. Also verify the $SPLUNK_HOME/var/log/splunk/migration.log, this will tell you which files have been modified. What you are mostly concered about is the fishbucket directory.

Here some additional reading:

Migrating_from_a_light_forwarder

Upgradethenixuniversalforwarder

what-is-this-fishbucket-thing - Found this very informative, but a little out of date.

Hope this helps or gets you started.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...