Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Does splunk clean all remove server names?

$
0
0
We are trying to put our Splunk Indexer on a Windows system image. Based on the documentation, stopping the Splunk service and issuing the `.\splunk clean all` command should clean out everything so the system image can be sysprep'd and in the future reimaged elsewhere. When we do this we see that the original server name still exists in the cloned image upon startup. Shouldn't the clean all command clean out the following? 1) var\log\splunk\ directory 2) var\lib\splunk\\* directories 3) var\run\splunk\* directory I'm guessing that even if it did the above directories, that it would be some manual effort to clean out the following user/app directories: 1) etc\apps\splunk_management_console\lookups\assets.csv 2) etc\users\admin\launcher\history\.csv 3) etc\users\admin\search\history\.csv 4) etc\users\admin\splunk_app_windows_infrastructure\history\.csv I don't think the users\admin directories would cause problems, but the splunk_management_console lookup file now has the template windows image server name in its assets file, when it wont exist in the deployment. So would the best practice be to search for the template server name anywhere in the splunk deployment prior to running sysprep cloning the image? thx.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>