<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to setup basic deployment for universalforwarder? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28859#M729</link>
    <description>&lt;P&gt;Are you literally doing 'grep' from the command line, or using Splunk search? Splunk search won't find PackageDownload by itself, because that term doesn't exist "in isolation"; you'd have to search for the full PackageDownloadRestHandler.&lt;/P&gt;

&lt;P&gt;But I'm going to guess that this client just doesn't know it's supposed to get the app. Does the host show up in &lt;CODE&gt;splunk list deploy-clients&lt;/CODE&gt;?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Nov 2012 03:42:10 GMT</pubDate>
    <dc:creator>sowings</dc:creator>
    <dc:date>2012-11-09T03:42:10Z</dc:date>
    <item>
      <title>how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28854#M724</link>
      <description>&lt;P&gt;What am I missing?  (new to splunk, but have been reading all about deployment servers)&lt;/P&gt;

&lt;P&gt;test environment with 2 servers --&lt;BR /&gt;&lt;BR /&gt;
Splunk 5 installed as deployment server  @ server named x.y.z&lt;BR /&gt;&lt;BR /&gt;
Splunk UniversalForwarder 5 installed on client @ server name austest&lt;/P&gt;

&lt;P&gt;On Deployment Server:&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;&lt;EM&gt;$SPLUNKHOME/etc/system/local/serverclass.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
[serverClass:testing]&lt;BR /&gt;&lt;BR /&gt;
filterType = whitelist&lt;BR /&gt;&lt;BR /&gt;
repositoryLocation = /opt/splunk/etc/deployment-apps/testing/&lt;BR /&gt;&lt;BR /&gt;
whitelist.0 = aus*  &lt;/P&gt;

&lt;P&gt;Placed &lt;EM&gt;inputs.conf&lt;/EM&gt; and &lt;EM&gt;outputs.conf&lt;/EM&gt; at:&lt;BR /&gt;&lt;BR /&gt;
&lt;EM&gt;$SPLUNKHOME/etc/deployment-apps/testing/default&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;outputs.conf&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
[tcpout]&lt;BR /&gt;&lt;BR /&gt;
disabled = false&lt;BR /&gt;&lt;BR /&gt;
defaultGroup=splunkPOC&lt;BR /&gt;&lt;BR /&gt;
[tcpout:splunkPOC]&lt;BR /&gt;&lt;BR /&gt;
server=x.y.z:9997&lt;BR /&gt;&lt;BR /&gt;
[tcpout-server://x.y.z:9997]  &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;inputs.conf&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
[monitor:///var/log/messages]&lt;BR /&gt;&lt;BR /&gt;
disabled=false&lt;BR /&gt;&lt;BR /&gt;
sourcetype=syslog  &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;On client:&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;EM&gt;$SPLUNKHOME/etc/system/local/deploymentclient.conf&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;
[target-broker:deploymentServer]&lt;BR /&gt;&lt;BR /&gt;
targetUri = x.y.z:8089&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;Enabled the receiver tcp port 9997 on the indexer. (Previously done when testing a 'non-deployment server' setup, which was full functional on forwarding from the client.)&lt;/P&gt;

&lt;P&gt;Reloaded deploy-server&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;&lt;EM&gt;/opt/splunk/bin/splunk reload deploy-server&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Check that client is configured:&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;&lt;EM&gt;/opt/splunkforwarder/bin/splunk list deploy-poll&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;EM&gt;Deployment Server URI is set to "x.y.z:8089".&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;I can see the client reaching the deployment server (at Splunk Web) and via:&lt;BR /&gt;&lt;BR /&gt;
(at deployment server)&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;&lt;EM&gt;/opt/splunk/bin/splunk list deploy-clients | grep 'hostname:'&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;EM&gt;hostname:       austest&lt;/EM&gt;  &lt;/P&gt;

&lt;P&gt;But the client doesn't appear to retrieve the &lt;STRONG&gt;inputs.conf&lt;/STRONG&gt;  or &lt;STRONG&gt;outputs.conf&lt;/STRONG&gt;  &lt;/P&gt;

&lt;P&gt;(at client)&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;&lt;EM&gt;/opt/splunkforwarder/bin/splunk list forward-server&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;EM&gt;Active forwards:&lt;BR /&gt;&lt;BR /&gt;
        None&lt;BR /&gt;&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;&lt;BR /&gt;
        None&lt;/EM&gt;  &lt;/P&gt;

&lt;P&gt;No data is forwarded from the client.&lt;BR /&gt;
What is wrong?&lt;BR /&gt;&lt;BR /&gt;
Where should the files be located after retrieval from the deployment server?&lt;BR /&gt;&lt;BR /&gt;
(Manual configuration works for the client to send data, but obviously isn't scalable.)&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 21:35:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28854#M724</guid>
      <dc:creator>kyless</dc:creator>
      <dc:date>2012-11-08T21:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28855#M725</link>
      <description>&lt;P&gt;If the app is called 'testing', the repositoryLocation you've specified are wrong. It's expected to be the directory &lt;EM&gt;containing&lt;/EM&gt; the apps (e.g. $SPLUNK_HOME/etc/deployment-apps), not the name of the app itself.&lt;/P&gt;

&lt;P&gt;Note that when the app is deployed to the client, it will be deployed to the $SPLUNK_HOME/etc/apps, so you can check the the filesystem for that. You may need to include a metadata/local.meta (to indicate sharing permissions) for the app in question. You may also need an app.conf in the app's local/ subdir.&lt;/P&gt;

&lt;P&gt;Finally, changes to inputs.conf typically require a restart, so you won't see that system as a forwarder until the forwarder system has had its Splunk daemon restarted.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 21:43:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28855#M725</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-11-08T21:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28856#M726</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;I am not trying to install an app, just basic universalforwarder configuration.  Installation of the *Nix app will come later if I can get the basics down.&lt;/P&gt;

&lt;P&gt;I have tried restarting the client, with no joy.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 22:03:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28856#M726</guid>
      <dc:creator>kyless</dc:creator>
      <dc:date>2012-11-08T22:03:35Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28857#M727</link>
      <description>&lt;P&gt;When you said that you created an inputs.conf and outputs.conf in the testing/default directory, you were in fact creating an "app" called testing, that should be sent to the client. The client will request it from the DS; this logs via a facility called PackageDownloadRestHandler. Grep for that in your splunkd.log on the DS.&lt;/P&gt;

&lt;P&gt;It sounds like the client doesn't realize that it needs the app, &lt;EM&gt;OR&lt;/EM&gt; the app isn't installing correctly. Did you update repositoryLocation in serverclass.conf, and reload deploy-server?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 22:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28857#M727</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-11-08T22:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28858#M728</link>
      <description>&lt;P&gt;Ok.  I'm new, thanks for helping get my mind around terminology.&lt;/P&gt;

&lt;P&gt;I'm basically following --&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Extendedexampledeployseveralstandardforwarders"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Extendedexampledeployseveralstandardforwarders&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I had used Splunk Web to create the serverclass configuration and it required a 'repository location'.   I've now changed the serverclass.conf to reflect the base repository --&lt;/P&gt;

&lt;P&gt;repositoryLocation = $SPLUNK_HOME/etc/deployment-apps&lt;/P&gt;

&lt;P&gt;restarted Splunk on the DS &lt;BR /&gt;
restarted Splunk on the client&lt;/P&gt;

&lt;P&gt;Grepping for 'PackageDownload' doesn't show up on the DS logs, historical or new.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2012 22:58:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28858#M728</guid>
      <dc:creator>kyless</dc:creator>
      <dc:date>2012-11-08T22:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28859#M729</link>
      <description>&lt;P&gt;Are you literally doing 'grep' from the command line, or using Splunk search? Splunk search won't find PackageDownload by itself, because that term doesn't exist "in isolation"; you'd have to search for the full PackageDownloadRestHandler.&lt;/P&gt;

&lt;P&gt;But I'm going to guess that this client just doesn't know it's supposed to get the app. Does the host show up in &lt;CODE&gt;splunk list deploy-clients&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 03:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28859#M729</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-11-09T03:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28860#M730</link>
      <description>&lt;P&gt;Yes.  Using grep from command line at both the DS and client against:&lt;BR /&gt;
$SPLUNK_HOME/var/log/splunk/*&lt;/P&gt;

&lt;P&gt;Yes. Client name appears on the DS when I run 'splunk list deploy-clients'.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 17:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28860#M730</guid>
      <dc:creator>kyless</dc:creator>
      <dc:date>2012-11-09T17:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28861#M731</link>
      <description>&lt;P&gt;Ok, so the client is phoning home (good), but not realizing that it has to download the app, since you're not seeing it in PackageDownloadRestHandler.&lt;/P&gt;

&lt;P&gt;If the snippet of serverclass.conf you're provided above is the whole thing, you may be missing an app declaration (i.e., send &lt;EM&gt;this&lt;/EM&gt; app to servers in &lt;EM&gt;this&lt;/EM&gt; class).&lt;/P&gt;

&lt;P&gt;Consider adding &lt;CODE&gt;[serverClass:testing:app:testing]&lt;/CODE&gt; to your serverclass.conf and reload the deployment server.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Nov 2012 17:58:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28861#M731</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-11-09T17:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28862#M732</link>
      <description>&lt;P&gt;Were you ultimately able to get this working?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2012 21:45:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28862#M732</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-11-13T21:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: how to setup basic deployment for universalforwarder?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28863#M733</link>
      <description>&lt;P&gt;Sorry for the delay.  Other items took priority.&lt;/P&gt;

&lt;P&gt;Adding in the [serverClass:testing:app:testing] to the serverclass.conf worked.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2012 21:17:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/how-to-setup-basic-deployment-for-universalforwarder/m-p/28863#M733</guid>
      <dc:creator>kyless</dc:creator>
      <dc:date>2012-11-14T21:17:29Z</dc:date>
    </item>
  </channel>
</rss>

