<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Deployment Server clients have wrong apps in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682041#M18957</link>
    <description>&lt;P&gt;We have a small satellite deployment of 40+ servers, that have a dedicated HF doubling as a Deployment Server running on Linux.&amp;nbsp; Equal mix of Windows and Linux.&amp;nbsp; 24h ago discovered that a few of the Windows servers were now reporting that they no longer had the Windows_TA installed, but instead were running the Linux_TA.&amp;nbsp; Checking the UF hosts directly, they in fact were running the Windows_TA even though the DS was reporting they were running the Linux_TA??&lt;BR /&gt;&lt;BR /&gt;After a day of trying to figure out how (validated filters, tested, removed and readded all Server Classes, and Apps), it continued.&amp;nbsp; Noticed throughout the day a few more were now reporting this "mix-up", and again validated those reporting Linux_TA were running Windows_TA.&amp;nbsp; As a final drastic measure, removed Splunk from the host (the HF/DS, not the UF's), reinstalled from scratch, and created the environment new.&amp;nbsp; Made sure the UF's were not running any of the distributed apps/ta's.&amp;nbsp; Built new Apps, Server Class.&amp;nbsp; The UF's started phoning home, and once again, the Windows servers were reporting the Linux_TA, but running the Windows_TA&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2024 19:22:20 GMT</pubDate>
    <dc:creator>tlmayes</dc:creator>
    <dc:date>2024-03-26T19:22:20Z</dc:date>
    <item>
      <title>Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682041#M18957</link>
      <description>&lt;P&gt;We have a small satellite deployment of 40+ servers, that have a dedicated HF doubling as a Deployment Server running on Linux.&amp;nbsp; Equal mix of Windows and Linux.&amp;nbsp; 24h ago discovered that a few of the Windows servers were now reporting that they no longer had the Windows_TA installed, but instead were running the Linux_TA.&amp;nbsp; Checking the UF hosts directly, they in fact were running the Windows_TA even though the DS was reporting they were running the Linux_TA??&lt;BR /&gt;&lt;BR /&gt;After a day of trying to figure out how (validated filters, tested, removed and readded all Server Classes, and Apps), it continued.&amp;nbsp; Noticed throughout the day a few more were now reporting this "mix-up", and again validated those reporting Linux_TA were running Windows_TA.&amp;nbsp; As a final drastic measure, removed Splunk from the host (the HF/DS, not the UF's), reinstalled from scratch, and created the environment new.&amp;nbsp; Made sure the UF's were not running any of the distributed apps/ta's.&amp;nbsp; Built new Apps, Server Class.&amp;nbsp; The UF's started phoning home, and once again, the Windows servers were reporting the Linux_TA, but running the Windows_TA&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 19:22:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682041#M18957</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-03-26T19:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682157#M18971</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/84018"&gt;@tlmayes&lt;/a&gt;, How are you whitelisting the hosts? Do you just want to use this nice feature of filtering everything by the OS type? Screenshot below -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="meetmshah_0-1711564328420.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29918i369751AE1E6CD21B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="meetmshah_0-1711564328420.png" alt="meetmshah_0-1711564328420.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With the above way, you can create 2 separate server classes for Windows and Linux and whitelist all the hosts.&lt;/P&gt;&lt;P&gt;Please accept the solution and hit Karma, if this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 18:33:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682157#M18971</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-03-27T18:33:18Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682160#M18973</link>
      <description>&lt;P&gt;Yes, filtering by OS.&amp;nbsp; Rebuilt the DS from scratch, set filters (using the OS filter).&amp;nbsp; All Linux servers receive the Linux TA.&amp;nbsp; All Windows Servers receive the Linux TA, and confirmed the OS filter, again &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 18:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682160#M18973</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-03-27T18:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682161#M18974</link>
      <description>&lt;P&gt;Would you mind sharing the&amp;nbsp;serverclass.conf file?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 18:41:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682161#M18974</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-03-27T18:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682168#M18979</link>
      <description>&lt;P&gt;Pretty simple....&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;serverClass:All:app:all_outputs]
restartSplunkWeb = 0
restartSplunkd = 1
stateOnClient = enabled

[serverClass:All]
whitelist.0 = *

[serverClass:Windows:app:Splunk_TA_windows]
restartSplunkWeb = 0
restartSplunkd = 1
stateOnClient = enabled

[serverClass:Linux:app:Splunk_TA_nix]
restartSplunkWeb = 0
restartSplunkd = 1
stateOnClient = enabled

[serverClass:All:app:all_deploymentclient]
restartSplunkWeb = 0
restartSplunkd = 1
stateOnClient = enabled

[serverClass:Linux]
machineTypesFilter = linux-x86_64
whitelist.0 = *

[serverClass:Windows]
machineTypesFilter = windows-x64
whitelist.0 = *&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 19:02:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682168#M18979</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-03-27T19:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682170#M18980</link>
      <description>Hi&lt;BR /&gt;can you told the base information of your environment (OS, version, splunk version, TA versions, UF versions etc.)?&lt;BR /&gt;Have you update something lately etc.?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Wed, 27 Mar 2024 19:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682170#M18980</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-27T19:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682171#M18981</link>
      <description>&lt;P&gt;Seems fairly simple / basic configurations. I would suggest raising Support case to get this troubleshot and fixed.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;thoughts?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 19:05:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682171#M18981</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2024-03-27T19:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682173#M18982</link>
      <description>&lt;P&gt;Everything is shiny "new".&amp;nbsp; This is a satellite to our full implementation, hosted in AWS.&amp;nbsp;&lt;BR /&gt;Splunk 9.2.0.1 on both agents and the DS (which doubles as an HF) running on AWS RHEL 8.9.&amp;nbsp; UF's are all running 9.2.0.&amp;nbsp; Less than 40 total agents (14 Win, 26 nix).&amp;nbsp;&lt;/P&gt;&lt;P&gt;DS was acting up, so destroyed it and built new.&amp;nbsp; Instantly, the same problem.&amp;nbsp; Even tried adding hostnames to the filter vice using wildcard.&amp;nbsp; Same.&amp;nbsp; The odd thing.&amp;nbsp; The DS reports that Windows hosts are running the Linux TA, but when you check the Windows hosts, they are running the Windows TA as they should be&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 19:30:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682173#M18982</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-03-27T19:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682174#M18983</link>
      <description>Have you local indexes on DS or are you sending logs to your real indexers? This has changes on 9.2.x and it could cause something weird.&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Mar 2024 19:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682174#M18983</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-27T19:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682176#M18984</link>
      <description>&lt;P&gt;I opened a P2 3 days ago... still waiting.&amp;nbsp; Typical&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 19:35:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682176#M18984</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-03-27T19:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682181#M18986</link>
      <description>&lt;P&gt;Great point, and something I did not know beforehand.&amp;nbsp; In troubleshooting stumbled onto the documentation stating what you are pointing out, the new _ds* indexes.&amp;nbsp; So yes, the _ds* indexes are local to the DS.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 20:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682181#M18986</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-03-27T20:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682203#M18991</link>
      <description>&lt;P&gt;Based on docs this should works. BUT on example part those platform selections have done on app not serverclass level. Maybe you should try that?&lt;/P&gt;&lt;P&gt;Btw have you configured this by gui or manually with text editor?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 23:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682203#M18991</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-27T23:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682267#M18996</link>
      <description>&lt;P&gt;Such a small and straightforward environment I used GUI.&amp;nbsp; I get the sense there is a bug in 9.2.0.x&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 11:30:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682267#M18996</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-03-28T11:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682294#M19000</link>
      <description>Ok, then it’s best to wait resolution for your P2 case.</description>
      <pubDate>Thu, 28 Mar 2024 15:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/682294#M19000</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-03-28T15:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/683057#M19066</link>
      <description>&lt;P&gt;Splunk support concluded it was an "as yet discovered software bug"&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 15:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/683057#M19066</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-04-03T15:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/685435#M19234</link>
      <description>&lt;P&gt;I have nothing to add, except to say that I have observed the same bug, where the server classes that use machine filtering display the incorrect clients in the UI.&lt;/P&gt;&lt;P&gt;The bug remains in version v.9.2.1&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 09:45:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/685435#M19234</guid>
      <dc:creator>hmallett</dc:creator>
      <dc:date>2024-04-25T09:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/685464#M19236</link>
      <description>&lt;P&gt;I believe that this bug is planned to be fixed in 9.2.2&lt;/P&gt;</description>
      <pubDate>Thu, 25 Apr 2024 13:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/685464#M19236</guid>
      <dc:creator>hmallett</dc:creator>
      <dc:date>2024-04-25T13:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/689571#M19508</link>
      <description>&lt;P&gt;From what *I* have seen, the machineTypesFilter seems to be at the root of this bug.&lt;/P&gt;&lt;P&gt;This is the absolute *WORST* update that I've seen in the last 6 years that I've been working with Splunk.&lt;/P&gt;&lt;P&gt;I did read something that would indicate that the (white|black)list.X can also take OS Strings, but the docs call it "platform dependent", so I am putting it off until we can actually SEE what's being deployed again.&lt;/P&gt;&lt;P&gt;I have noticed yet *ANOTHER* bug...&amp;nbsp; After a Deployment Server has been running for a bit, ANY CALL that would query DS Client information will TIMEOUT.&lt;/P&gt;&lt;P&gt;I have multiple scripts that read data from /services/deployment/server/clients, and I've bumped the timeouts to 30 seconds, and it still times-out.&amp;nbsp; It used to take &amp;lt; 2s to pull data from THOUSANDS of clients.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2024 15:15:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/689571#M19508</guid>
      <dc:creator>mortification77</dc:creator>
      <dc:date>2024-06-04T15:15:27Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/700879#M20407</link>
      <description>&lt;P class="lia-indent-padding-left-30px"&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/84018"&gt;@tlmayes&lt;/a&gt;,&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;i have a same issue.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;Any solutions for this? Pls&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 12:25:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/700879#M20407</guid>
      <dc:creator>hieuba6868</dc:creator>
      <dc:date>2024-10-03T12:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment Server clients have wrong apps</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/700881#M20408</link>
      <description>&lt;P&gt;Has been officially registered as a bug.&amp;nbsp; No ETA on fix&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 13:13:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-clients-have-wrong-apps/m-p/700881#M20408</guid>
      <dc:creator>tlmayes</dc:creator>
      <dc:date>2024-10-03T13:13:00Z</dc:date>
    </item>
  </channel>
</rss>

