<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Output and deployment client configs constantly overwritten in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569749#M101015</link>
    <description>&lt;P&gt;Nope, I don't have anything like that.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Oct 2021 17:57:37 GMT</pubDate>
    <dc:creator>whar_garbl</dc:creator>
    <dc:date>2021-10-05T17:57:37Z</dc:date>
    <item>
      <title>Output and deployment client configs constantly overwritten</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569714#M101011</link>
      <description>&lt;P&gt;I have a single-instance Splunk setup with a handful of Universal Forwarders sending in data. There was previously a different architecture on this network, but this is a new build from the ground up - everything is new builds and fresh installs (all version 8.2.2.1; server is RHEL 8; clients are Windows 10).&amp;nbsp;&lt;/P&gt;&lt;P&gt;My UFs are installed with command line options to set the forwarding server and deployer (the same place). However, periodically, the clients' outputs.conf and deploymentclient.conf are being overwritten, and I cannot for the life of me figure out why. The settings being pushed in are for the old architecture, none of which remains on the network. Also, notably, it seems to only be the Windows UFs that are getting their settings overwritten - my *nix boxes do not appear to be affected as of now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have attached a ProcMon to monitor the file edits. The changes are coming from splunkd.exe via the REST API:&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;C:\Program Files\SplunkUniversalForwarder\bin\splunkd rest --noauth POST /services/data/outputs/tcp/server/ name=wrong_server.domain.com:9997&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;C:\Program Files\SplunkUniversalForwarder\bin\splunkd rest --noauth POST /services/admin/deploymentclient/deployment-client/ targetUri=wrong_deployer.domain.com:8089&lt;/LI-CODE&gt;&lt;P&gt;I haven't yet found a way to manually elicit this change, and the update interval seems to vary from just a few minutes to every couple of hours. I've scoured my Group Policy and have not found any relevant settings there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm stumped. Does anyone have any ideas as to what may be doing this?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 15:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569714#M101011</guid>
      <dc:creator>whar_garbl</dc:creator>
      <dc:date>2021-10-05T15:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Output and deployment client configs constantly overwritten</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569747#M101014</link>
      <description>&lt;P&gt;You've ruled out GPO.&amp;nbsp; Does your company have another management utility, like BigFix, Puppet, or Ansible?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 17:54:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569747#M101014</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-10-05T17:54:04Z</dc:date>
    </item>
    <item>
      <title>Re: Output and deployment client configs constantly overwritten</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569749#M101015</link>
      <description>&lt;P&gt;Nope, I don't have anything like that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 17:57:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569749#M101015</guid>
      <dc:creator>whar_garbl</dc:creator>
      <dc:date>2021-10-05T17:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Output and deployment client configs constantly overwritten</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569764#M101019</link>
      <description>&lt;P&gt;I figured it out.&lt;/P&gt;&lt;P&gt;Someone had set a compliance baseline in SCCM to check and overwrite the conf files if they didn't match a specified value. Somehow that had been lingering for a couple of years without being disabled. Oops.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Oct 2021 18:46:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Output-and-deployment-client-configs-constantly-overwritten/m-p/569764#M101019</guid>
      <dc:creator>whar_garbl</dc:creator>
      <dc:date>2021-10-05T18:46:21Z</dc:date>
    </item>
  </channel>
</rss>

