<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deployment Server - Preventing use of Local Created Apps in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/585283#M11588</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/191266"&gt;@shocko&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the correct approach is to create an App (I usually call TA_Forwarders) containing only two files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;deploymentclient.conf (to address and manage the connection with the DS),&lt;/LI&gt;&lt;LI&gt;outputs.conf (to address and manage the connection with the Indexers).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In this way you have in only one point the configuratins to reach DS and Indexers, so you can easily make every change (e.g. changeing DS or adding an Indexers).&lt;/P&gt;&lt;P&gt;If your client is connected to the DS, every added App or every local change is deleted at the first check.&lt;/P&gt;&lt;P&gt;The only problem is that, when you install a new Forwarder, you have to manually copy this App on the Client and locally restart Splunk, then it's in the managing cycle.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Wed, 16 Feb 2022 07:13:06 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2022-02-16T07:13:06Z</dc:date>
    <item>
      <title>Deployment Server - Preventing use of Local Created Apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583919#M11489</link>
      <description>&lt;P&gt;I'm using Splunk Enterprise 8.2.4 with deployment server. I wat to push out all config/apps to my forwarders to prevent server admins adding config/apps locally. To date system admins have been creating their own inputs and dumping data into main, flooding the license usages etc. and I need to stop this happening. I only want approved configs/inputs etc. to be pushed to the forwarders. As such, I have onboarded all my forwarders to deployment server. My first question is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#800080"&gt;&lt;STRONG&gt;Q1&lt;/STRONG&gt;&lt;/FONT&gt;: How to prevent a user at the system creating an input and pushing data to the indexers? Is their a config item to only accept deployment server deployed inputs?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;On a test system I pushed an application I created that disabled the collection of the&amp;nbsp;[WinEventLog://Security]. I found though that that system had received the app but was still pushing those events. Running btool at the forwarder shows:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf [WinEventLog://Security]&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf disabled = 0&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;So this seems to be the config from when the forwarder&amp;nbsp;was installed ad the windows inputs were selected in the forwarder&amp;nbsp;MSI installation&amp;nbsp;UI. &lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#800080"&gt;&lt;STRONG&gt;Q2&lt;/STRONG&gt;&lt;/FONT&gt;: How to override this with deployment server i.e. a locally configured input not necessarily&amp;nbsp;in the apps folder?&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 11:15:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583919#M11489</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-02-07T11:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server - Preventing use of Local Created Apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583925#M11490</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/191266"&gt;@shocko&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you configured your target server as a Deployment Client, managed by the Deployment Server, each local update on the target server is deleted at the next DS check.&lt;/P&gt;&lt;P&gt;To avoid every change, it's a good practice to put also deployment_client.conf file in a TA to deploy using the DS.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 11:53:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583925#M11490</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-07T11:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server - Preventing use of Local Created Apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583933#M11492</link>
      <description>&lt;P&gt;Thanks for the reply. The file&amp;nbsp;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf&amp;nbsp;&lt;/EM&gt;&lt;/FONT&gt;would have existed before the system was onboarded onto the deployment&amp;nbsp;server but even after forwarder check-in it persists. So does this not indicate that only apps deployed by deployment server are enforced and locally created ones are not?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 13:00:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583933#M11492</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-02-07T13:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server - Preventing use of Local Created Apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583936#M11493</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/191266"&gt;@shocko&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;there are some internal&amp;nbsp;apps that cannot be used and that aren't managed by the Deployment Server,&amp;nbsp;&amp;nbsp;&lt;EM&gt;SplunkUniversalForwarder in one of them!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Ciao.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Giuseppe&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 13:10:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583936#M11493</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-07T13:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server - Preventing use of Local Created Apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583951#M11495</link>
      <description>&lt;P&gt;OK. That says to me that deployment server can only be used to deliver applications per ya and not to control an arbitrary one ? Or, do you mean that I should deploy this to the SplunkUniversalForwarder app ?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 14:14:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583951#M11495</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-02-07T14:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server - Preventing use of Local Created Apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583953#M11496</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/191266"&gt;@shocko&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;DS can be used to deploy and control every App to Clients.&lt;/P&gt;&lt;P&gt;There are some internal app, installed during installation and that cannot be modified, that aren't managed by DS.&lt;/P&gt;&lt;P&gt;Every other App is managed by DS.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 14:17:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/583953#M11496</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-07T14:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server - Preventing use of Local Created Apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/585233#M11583</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;, I don't understand what you man by&lt;/P&gt;&lt;P&gt;&lt;FONT color="#993300"&gt;&lt;EM&gt;To avoid every change, it's a good practice to put also deployment_client.conf file in a TA to deploy using the DS.&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Can you elaborate?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 20:44:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/585233#M11583</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-02-15T20:44:04Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server - Preventing use of Local Created Apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/585283#M11588</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/191266"&gt;@shocko&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the correct approach is to create an App (I usually call TA_Forwarders) containing only two files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;deploymentclient.conf (to address and manage the connection with the DS),&lt;/LI&gt;&lt;LI&gt;outputs.conf (to address and manage the connection with the Indexers).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In this way you have in only one point the configuratins to reach DS and Indexers, so you can easily make every change (e.g. changeing DS or adding an Indexers).&lt;/P&gt;&lt;P&gt;If your client is connected to the DS, every added App or every local change is deleted at the first check.&lt;/P&gt;&lt;P&gt;The only problem is that, when you install a new Forwarder, you have to manually copy this App on the Client and locally restart Splunk, then it's in the managing cycle.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 16 Feb 2022 07:13:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Preventing-use-of-Local-Created-Apps/m-p/585283#M11588</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-16T07:13:06Z</dc:date>
    </item>
  </channel>
</rss>

