<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log source with 2 deployment app send log from only 1 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684482#M19150</link>
    <description>&lt;P&gt;Hi Splunkers,&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a Windows log source with a UF installed on it. We have no access to this log source: we only know that we collect Windows logs via UF and it works properly. Collected logs are the usual one: Security, Applications, and so on.&lt;BR /&gt;Starting from today, we need to add a monitor input: some files are stored in a folder and we need to collect them. So, on our DS, we created another app, inside &lt;STRONG&gt;deployment-app&lt;/STRONG&gt; folder, with a proper &lt;STRONG&gt;inputs.conf&lt;/STRONG&gt; and &lt;STRONG&gt;props.conf &lt;/STRONG&gt;and then we deployed it.&lt;BR /&gt;Why we created another app and does not simply added a monitor stanza in inputs.conf for Windows addon? Simply because Windows addon is deployed on many host; on the other side, we need to monitor the path only on 1 specific host, so we preferred to deploy another dedicated app, with its server class and so on.&lt;/P&gt;&lt;P&gt;DS give no error; app is shown as deployed with no issues. At the same time, we got no error looking on &lt;STRONG&gt;splunkd.log&lt;/STRONG&gt; and/or &lt;STRONG&gt;_internal&lt;/STRONG&gt; index. By the way, logs are not collected.&lt;BR /&gt;For sure, we are going to reach Host owner and perform basic checks, like:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is provided path the right one?&lt;/LI&gt;&lt;LI&gt;User in charge of execute UF has read permission on that folder?&lt;/LI&gt;&lt;LI&gt;In UF app folder, is the one deployed by us viewable?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;But before this, there is a doubt I have: above point 2, in case of permission denied, I should see in _internal logs some error message, right? Because currently I don't see any error message related to this issue. The behavior is like the &lt;STRONG&gt;inputs.conf&lt;/STRONG&gt; we set in deployment app is totally ignored: searching on _internl and/or splunkd.log, I cannot see anything related to path we have to monitor.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Apr 2024 10:23:48 GMT</pubDate>
    <dc:creator>SplunkExplorer</dc:creator>
    <dc:date>2024-04-17T10:23:48Z</dc:date>
    <item>
      <title>Log source with 2 deployment app send log from only 1</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684482#M19150</link>
      <description>&lt;P&gt;Hi Splunkers,&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a Windows log source with a UF installed on it. We have no access to this log source: we only know that we collect Windows logs via UF and it works properly. Collected logs are the usual one: Security, Applications, and so on.&lt;BR /&gt;Starting from today, we need to add a monitor input: some files are stored in a folder and we need to collect them. So, on our DS, we created another app, inside &lt;STRONG&gt;deployment-app&lt;/STRONG&gt; folder, with a proper &lt;STRONG&gt;inputs.conf&lt;/STRONG&gt; and &lt;STRONG&gt;props.conf &lt;/STRONG&gt;and then we deployed it.&lt;BR /&gt;Why we created another app and does not simply added a monitor stanza in inputs.conf for Windows addon? Simply because Windows addon is deployed on many host; on the other side, we need to monitor the path only on 1 specific host, so we preferred to deploy another dedicated app, with its server class and so on.&lt;/P&gt;&lt;P&gt;DS give no error; app is shown as deployed with no issues. At the same time, we got no error looking on &lt;STRONG&gt;splunkd.log&lt;/STRONG&gt; and/or &lt;STRONG&gt;_internal&lt;/STRONG&gt; index. By the way, logs are not collected.&lt;BR /&gt;For sure, we are going to reach Host owner and perform basic checks, like:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Is provided path the right one?&lt;/LI&gt;&lt;LI&gt;User in charge of execute UF has read permission on that folder?&lt;/LI&gt;&lt;LI&gt;In UF app folder, is the one deployed by us viewable?&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;But before this, there is a doubt I have: above point 2, in case of permission denied, I should see in _internal logs some error message, right? Because currently I don't see any error message related to this issue. The behavior is like the &lt;STRONG&gt;inputs.conf&lt;/STRONG&gt; we set in deployment app is totally ignored: searching on _internl and/or splunkd.log, I cannot see anything related to path we have to monitor.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 10:23:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684482#M19150</guid>
      <dc:creator>SplunkExplorer</dc:creator>
      <dc:date>2024-04-17T10:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Log source with 2 deployment app send log from only 1</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684484#M19151</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249714"&gt;@SplunkExplorer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Did you check "Restart Splunkd" option for your new input app on app settings? Splunk Forwarder needs to be restarted for the new inputs.&lt;/P&gt;&lt;P&gt;.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="scelikok_0-1713350839538.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/30434iCCFAEB7CF41C11BD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="scelikok_0-1713350839538.png" alt="scelikok_0-1713350839538.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 10:48:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684484#M19151</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2024-04-17T10:48:18Z</dc:date>
    </item>
    <item>
      <title>Re: Log source with 2 deployment app send log from only 1</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684485#M19152</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;yes, it's first check I performed; restart splunkd is correctly flagged&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 10:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684485#M19152</guid>
      <dc:creator>SplunkExplorer</dc:creator>
      <dc:date>2024-04-17T10:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Log source with 2 deployment app send log from only 1</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684486#M19153</link>
      <description>&lt;P&gt;If there is a file read permission error you should have seen in _internal logs. &amp;nbsp;You can check if app is installed on your host using below query;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal component=PackageDownloadRestHandler host=YourHost app=YourAppName&lt;/LI-CODE&gt;&lt;P&gt;On my experience, most of the problems on this kind of blind configurations is given pathname or filename is wrong. &amp;nbsp;And please remember file inputs are case-sensitive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 11:02:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684486#M19153</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2024-04-17T11:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Log source with 2 deployment app send log from only 1</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684501#M19156</link>
      <description>&lt;P&gt;A very useful suggestion&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;, it is something new I learned. Thanks.&lt;/P&gt;&lt;P&gt;Executing this query I got some result; message says that "app bundle download has started and completed". The only think I don't know if it's right, is that host field is populated with DS hostname and not the log source one.&lt;/P&gt;&lt;P&gt;By the way, this lead me to agree with you about your last consideration: there must be some error in path/filename provided. We are going to check those parameter.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 12:12:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684501#M19156</guid>
      <dc:creator>SplunkExplorer</dc:creator>
      <dc:date>2024-04-17T12:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Log source with 2 deployment app send log from only 1</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684575#M19165</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249714"&gt;@SplunkExplorer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You are right that is Deployment Server log but it should show client ip address too. You can use below search to check deployment steps on client;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal  host=YourClientHost  sourcetype=splunkd (DeployedApplication OR ApplicationManager  OR "Restarting Splunkd")&lt;/LI-CODE&gt;&lt;P&gt;You should see similar events on regarding host logs;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;INFO  DeployedApplication - Checksum mismatch 0 &amp;lt;&amp;gt; 18281318892102154454 for app=your_app_name. Will reload from='x.x.x.x:8089/services/streams/deployment?name=default:your_serverclass_name:your_app_name'

INFO  DeployedApplication - Downloaded url=x.x.x.x:8089/services/streams/deployment?name=default:your_serverclass_name:your_app_name to file='C:\Program Files\SplunkUniversalForwarder\var\run\your_serverclass_name\your_app_name-1711990721.bundle' sizeKB=xx

INFO  DeployedApplication - Installing app=your_app_name to='C:\Program Files\SplunkUniversalForwarder\etc\apps\your_app_name'

INFO  ApplicationManager - Detected app creation:your_app_name

WARN  DC:DeploymentClient - Restarting Splunkd...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;If everything seems ok on these log, we can think the problem is on provided path/filename.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 21:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Log-source-with-2-deployment-app-send-log-from-only-1/m-p/684575#M19165</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2024-04-17T21:43:16Z</dc:date>
    </item>
  </channel>
</rss>

