<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk 6 Forwarder Management Question in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109529#M4137</link>
    <description>&lt;P&gt;Scenario&lt;/P&gt;

&lt;P&gt;Upgraded from Splunk 4 to Splunk 6. &lt;BR /&gt;
Using deployment server to distribute apps&lt;/P&gt;

&lt;P&gt;There are a large number of clients&lt;BR /&gt;
The target clients are placed in groups by setting common clientNames in deploymentclient.conf&lt;BR /&gt;
eg clientName=womble&lt;/P&gt;

&lt;P&gt;In serverclass.conf the class is defined :-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[serverClass:wombles]

[serverClass:wombles:app:myapp]
whitelist.0 = womble
restartSplunkd = true
continueMatching = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This used to deploy on Splunk v4 but does not on Splunk v6.0&lt;/P&gt;

&lt;P&gt;If this is added:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[global]
whitelist.0 = *
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The app is deployed to everything, not just the intended nodes&lt;/P&gt;

&lt;P&gt;I believe the above config is not compatible with the forwarder management GUI - but should still work&lt;/P&gt;

&lt;P&gt;If I move the whitelist to serverClass level it works&lt;BR /&gt;
Any ideas?&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2014 17:39:30 GMT</pubDate>
    <dc:creator>dshakespeare_sp</dc:creator>
    <dc:date>2014-01-10T17:39:30Z</dc:date>
    <item>
      <title>Splunk 6 Forwarder Management Question</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109529#M4137</link>
      <description>&lt;P&gt;Scenario&lt;/P&gt;

&lt;P&gt;Upgraded from Splunk 4 to Splunk 6. &lt;BR /&gt;
Using deployment server to distribute apps&lt;/P&gt;

&lt;P&gt;There are a large number of clients&lt;BR /&gt;
The target clients are placed in groups by setting common clientNames in deploymentclient.conf&lt;BR /&gt;
eg clientName=womble&lt;/P&gt;

&lt;P&gt;In serverclass.conf the class is defined :-&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[serverClass:wombles]

[serverClass:wombles:app:myapp]
whitelist.0 = womble
restartSplunkd = true
continueMatching = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This used to deploy on Splunk v4 but does not on Splunk v6.0&lt;/P&gt;

&lt;P&gt;If this is added:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[global]
whitelist.0 = *
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The app is deployed to everything, not just the intended nodes&lt;/P&gt;

&lt;P&gt;I believe the above config is not compatible with the forwarder management GUI - but should still work&lt;/P&gt;

&lt;P&gt;If I move the whitelist to serverClass level it works&lt;BR /&gt;
Any ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 17:39:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109529#M4137</guid>
      <dc:creator>dshakespeare_sp</dc:creator>
      <dc:date>2014-01-10T17:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6 Forwarder Management Question</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109530#M4138</link>
      <description>&lt;P&gt;&lt;STRONG&gt;UPDATE&lt;/STRONG&gt;: After further research, the first assumption below turns out to be incorrect: It is &lt;STRONG&gt;not&lt;/STRONG&gt; necessary for each deployment client to be configured with a unique clientName.&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;&lt;CODE&gt;The target clients are placed in groups by setting common clientNames in deploymentclient.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I think that you are breaching a basic client/server contract for this feature by giving the same clientName to more than one client. Although the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Deploymentclientconf"&gt;spec file for deploymentclient.conf&lt;/A&gt; doesn't say so, I'm fairly certain that each client should have a unique clientName or all bets are off.&lt;/P&gt;

&lt;P&gt;I'd suggest addressing that problem and seeing if things work again as you would expect.  &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;I believe the above config is not compatible with the forwarder management GUI&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;That is correct. App-level directives in serverclass.conf are not supported by the Forwarder Management UI.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2014 19:02:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109530#M4138</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2014-01-10T19:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6 Forwarder Management Question</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109531#M4139</link>
      <description>&lt;P&gt;hi dshakespeare_splunk,&lt;/P&gt;

&lt;P&gt;Please:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;post your &lt;EM&gt;entire&lt;/EM&gt; &lt;CODE&gt;serverclass.conf&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;specify exactly what you mean by "does not work": what behavior is observed, and how is this different from the expected behavior?&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 10 Jan 2014 23:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109531#M4139</guid>
      <dc:creator>V_at_Splunk</dc:creator>
      <dc:date>2014-01-10T23:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6 Forwarder Management Question</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109532#M4140</link>
      <description>&lt;P&gt;Above is the complete file.&lt;BR /&gt;
Looking at spec file - it appears we do not support whitelist at app level only global and serverClass level&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jan 2014 12:01:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109532#M4140</guid>
      <dc:creator>dshakespeare_sp</dc:creator>
      <dc:date>2014-01-13T12:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk 6 Forwarder Management Question</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109533#M4141</link>
      <description>&lt;P&gt;In the current version, you have the whitelist in the wrong location. It should be under the main server class stanza not it's child app one. As below.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[serverClass:wombles]
whitelist.0 = womble

[serverClass:wombles:app:myapp]
restartSplunkd = true
continueMatching = false
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Aug 2014 00:30:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-6-Forwarder-Management-Question/m-p/109533#M4141</guid>
      <dc:creator>bmunson_splunk</dc:creator>
      <dc:date>2014-08-27T00:30:50Z</dc:date>
    </item>
  </channel>
</rss>

