Reporting

How to export forwarder configuration

xabidh
New Member

Hi,

I have installed the forwarder in DC and other server as Indexer.
I do not know how was installed.
I would like to export Forwarder configuration because I have to install a new Forwarder with the same configuration to delete the old one.
What files need to be copied / check?

Thanks in advance.

0 Karma
1 Solution

asimagu
Builder

This is usually configured inside the SplunkForwarder app

$SPLUNK_HOME/etc/apps/SplunkForwarder

but it may be that you configured it in a different way...

View solution in original post

0 Karma

xabidh
New Member

Ok, thanks.

Is necessary change something in the Indexer server?

0 Karma

stmyers7941
Path Finder

The indexer needs to have an inputs.conf with [splunktcp://9997] stanza. You can check to see if your indexer is listening with netstat (assuming nix):
~ $ netstat -tnlp | grep 9997
tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN 24504/splunkd

0 Karma

xabidh
New Member

I already have this sentece in inputs.conf.
I supposed that is not needed in the Indexer point to Forwarder...
I see with the comand "netstat -a" something like that:
TCP [IP of indexer]:9997 [IP of forwarder]:62244

Thanks

0 Karma

vincenteous
Communicator

Hi xabidh,

If you want to implement existing configurations from old forwarder to the new one, I suggest you copy the entirety of $SPLUNK_HOME/etc folder. Copying this folders means you copy all installed apps of old forwarder, inputs.conf, outputs.conf, authentication, and other configurations which has previously been defined on the old one.

0 Karma

asimagu
Builder

This is usually configured inside the SplunkForwarder app

$SPLUNK_HOME/etc/apps/SplunkForwarder

but it may be that you configured it in a different way...

0 Karma

xabidh
New Member

Hi,
I have checked all files inside this folder C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder but I cannot find the file where its configured the indexer. What is the file name where should be contained the IP/name of indexer server?

Regards

0 Karma

MuS
Legend

check any available outputs.conf on your forwarder

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...