<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk Deployment server in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-Deployment-server/m-p/92565#M3388</link>
    <description>&lt;P&gt;deployment apps will not over write the settings in etc/system/local. You may find that you have some settings configured in etc/system/local that make more sense managing with a deployed application. If that is the case, you would have to comment out the setting in etc/system/local so that the application would control the setting. I would start out deploying apps one at a time to migrate system/local settings that make sense. Then most of the apps you deploy can contain new inputs or other functionallity.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Oct 2012 21:10:52 GMT</pubDate>
    <dc:creator>tskinnerivsec</dc:creator>
    <dc:date>2012-10-16T21:10:52Z</dc:date>
    <item>
      <title>splunk Deployment server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-Deployment-server/m-p/92564#M3387</link>
      <description>&lt;P&gt;When we first rolled out Splunk, the deployment server was not used.  Its been a while now &amp;amp; I want to move to a deployment server architecture.  My question is:&lt;/P&gt;

&lt;P&gt;Should I remove everything from etc/system/local that was put on the individual instances of Splunk or can I leave that and will the deployment apps override those?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2012 20:31:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-Deployment-server/m-p/92564#M3387</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2012-10-16T20:31:48Z</dc:date>
    </item>
    <item>
      <title>Re: splunk Deployment server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-Deployment-server/m-p/92565#M3388</link>
      <description>&lt;P&gt;deployment apps will not over write the settings in etc/system/local. You may find that you have some settings configured in etc/system/local that make more sense managing with a deployed application. If that is the case, you would have to comment out the setting in etc/system/local so that the application would control the setting. I would start out deploying apps one at a time to migrate system/local settings that make sense. Then most of the apps you deploy can contain new inputs or other functionallity.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2012 21:10:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-Deployment-server/m-p/92565#M3388</guid>
      <dc:creator>tskinnerivsec</dc:creator>
      <dc:date>2012-10-16T21:10:52Z</dc:date>
    </item>
    <item>
      <title>Re: splunk Deployment server</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-Deployment-server/m-p/92566#M3389</link>
      <description>&lt;P&gt;That's what I was figuring but I wanted to make sure.  I have basically migrated all settings for inputs/outputs/transforms/etc from conf files in /etc/system/local to their own apps to be managed, so its a matter of removing these from the conf files &amp;amp; syncing with the deployment server.&lt;/P&gt;

&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2012 12:45:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-Deployment-server/m-p/92566#M3389</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2012-10-17T12:45:37Z</dc:date>
    </item>
  </channel>
</rss>

