<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Deployment clients logging in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101081#M3729</link>
    <description>&lt;P&gt;Is the component in _internal dropped for the deployment clients connects ( component DeploymenServer) ?&lt;/P&gt;

&lt;P&gt;I believe that to get the client you could use :&lt;/P&gt;

&lt;P&gt;index=_internal source=&lt;EM&gt;splunkd.log&lt;/EM&gt; component="DeploymentServer" | dedup hostname | table hostname&lt;/P&gt;</description>
    <pubDate>Wed, 24 Oct 2012 13:17:23 GMT</pubDate>
    <dc:creator>Starlette</dc:creator>
    <dc:date>2012-10-24T13:17:23Z</dc:date>
    <item>
      <title>Deployment clients logging</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101081#M3729</link>
      <description>&lt;P&gt;Is the component in _internal dropped for the deployment clients connects ( component DeploymenServer) ?&lt;/P&gt;

&lt;P&gt;I believe that to get the client you could use :&lt;/P&gt;

&lt;P&gt;index=_internal source=&lt;EM&gt;splunkd.log&lt;/EM&gt; component="DeploymentServer" | dedup hostname | table hostname&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 13:17:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101081#M3729</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2012-10-24T13:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment clients logging</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101082#M3730</link>
      <description>&lt;P&gt;The clients themselves will log events as DeploymentClient (typically when the server has issued &lt;CODE&gt;splunk reload deploy-server&lt;/CODE&gt; to update the class definitions. It will also log DeployedApplication when the client has downloaded and installed a new app.&lt;/P&gt;

&lt;P&gt;The server will log PackageDownloadRestHandler messages in splunkd.log (including the IP of the client) when a client downloads an application. The server also logs client connections (even when no apps are being deployed) in splunkd_access.log, with the 'phonehome' keyword. Information about the client is logged here, such as its IP, server name (as defined in server.conf), etc.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 16:18:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101082#M3730</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-10-24T16:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment clients logging</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101083#M3731</link>
      <description>&lt;P&gt;cool, indeed it looks like the components are gone,,,,guess time for a deployment config monitor?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 11:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101083#M3731</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2012-10-25T11:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment clients logging</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101084#M3732</link>
      <description>&lt;P&gt;Components are gone? Perhaps I misunderstood the nature of your question? What exactly are you trying to figure out? Whether an individual client has connected?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 15:10:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101084#M3732</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-10-25T15:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment clients logging</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101085#M3733</link>
      <description>&lt;P&gt;yeah, or is ariving at the deploymentbox, i can control them now but was focus on the component deploymentserver which is gone in splunk.d log&lt;/P&gt;</description>
      <pubDate>Thu, 25 Oct 2012 20:01:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Deployment-clients-logging/m-p/101085#M3733</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2012-10-25T20:01:02Z</dc:date>
    </item>
  </channel>
</rss>

