<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Introducing Deployment Server Stops Data Getting In in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536494#M89925</link>
    <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;&lt;P&gt;thanks for your response.&lt;/P&gt;&lt;P&gt;So do you mean I *need* to monitor the DS? and so does the outputs.conf file only need to be there if the DS itself is being monitored?&amp;nbsp; Because it's not in the chain of process to Splunk Cloud here is it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, Anish&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2021 13:59:30 GMT</pubDate>
    <dc:creator>achauhan2098</dc:creator>
    <dc:date>2021-01-20T13:59:30Z</dc:date>
    <item>
      <title>Introducing Deployment Server Stops Data Getting In</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536446#M89918</link>
      <description>&lt;P&gt;Hi Community!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Despite lots of reading and doing my best to get the answer from documentation, I can't see why the introduction of a deployment server is causing issues with the data getting into Splunk Cloud.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I'd really appreciate some help.&lt;/P&gt;&lt;P&gt;I have 4 test servers and I've completed the steps below:&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Intermediate forwarders have Splunk cloud as forwarding servers in outputs.conf file. this is also verified when issuing cli commands.&lt;/LI&gt;&lt;LI&gt;Intermediate forwarders have a receiving port configured&lt;/LI&gt;&lt;LI&gt;Intermediate forwarders have the Splunk Cloud credentials installed&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;When the UF have the intermediate forwarders set as the forwarding server the cli shows that this config is good&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;-&amp;gt; and ultimately the forwarding client data reaches the cloud index no problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when I introduce the deployment server, this is where no data reaches Splunk cloud and issuing cli commands the forwarding client just hangs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I look in /etc/deployment-app/&amp;lt;app-folder&amp;gt;/default - there's no outputs.conf file on the deployment server and so I feel that the server config is missing something.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've used this guide as a setup reference for the deployment server but I still feel like I've missed something.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2011/Admin/WindowsGDI" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2011/Admin/WindowsGDI&lt;/A&gt;&amp;nbsp;(specifically step 3)&lt;/P&gt;&lt;P&gt;Any suggestions would be really appreciated,&lt;/P&gt;&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 08:21:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536446#M89918</guid>
      <dc:creator>achauhan2098</dc:creator>
      <dc:date>2021-01-20T08:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Introducing Deployment Server Stops Data Getting In</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536486#M89922</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230681"&gt;@achauhan2098&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the Deployment Server has the role to manage clients (Forwarders), but to monitor it, you have to consider it as a normal target and redirect its logs (through Intermediate Forwarders) to Indexers (on premise or Cloud), so outpus.conf should be in $SPLUNK_HOME/etc/system/local or (better) in a dedicated app.&lt;/P&gt;&lt;P&gt;The folder $SPLUNK_HOME&lt;SPAN&gt;/etc/deployment-app, it's used to contain the apps to deploy to the other Forwarders.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Infos at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Updating/Aboutdeploymentserver" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Updating/Aboutdeploymentserver&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 12:49:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536486#M89922</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-20T12:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Introducing Deployment Server Stops Data Getting In</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536494#M89925</link>
      <description>&lt;P&gt;Hi Giuseppe,&lt;/P&gt;&lt;P&gt;thanks for your response.&lt;/P&gt;&lt;P&gt;So do you mean I *need* to monitor the DS? and so does the outputs.conf file only need to be there if the DS itself is being monitored?&amp;nbsp; Because it's not in the chain of process to Splunk Cloud here is it?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, Anish&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 13:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536494#M89925</guid>
      <dc:creator>achauhan2098</dc:creator>
      <dc:date>2021-01-20T13:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Introducing Deployment Server Stops Data Getting In</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536673#M89961</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230681"&gt;@achauhan2098&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it's usually a best practice to monitor all your Splunk infrastructure, so I hint to redirect your DS's internal logs to Cloud, anyway you don't consume license!&lt;/P&gt;&lt;P&gt;If instead you don't want to monitor the DS, you don't need to have an outputs.conf in your DS.&lt;/P&gt;&lt;P&gt;It's different if you, (as hinted by best practices) deploy outputs.conf to your UFs using the DS: in this case you have to create a dedicated app (called e.g. TA_Forwarders or as you like) containing two files: outputs.conf and deploymentclient.conf.&lt;/P&gt;&lt;P&gt;In this case you have outputs.conf in $SPLUNK_HOME/etc/deployment-apps, but not in this folder, but in a TA (with the normal structure of a TA).&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 12:25:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/536673#M89961</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-21T12:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Introducing Deployment Server Stops Data Getting In</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/537117#M90030</link>
      <description>&lt;P&gt;Thanks for your help - I got this working.&amp;nbsp; I think the issue was ultimately with the forwarding.&amp;nbsp; It looks like the app for logging into Splunk Cloud was being sent to the UF. But I only got this working once I stripped the desired app down to just the inputs and outputs.conf files.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still have work to do but the base is there now.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 20:26:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/537117#M90030</guid>
      <dc:creator>achauhan2098</dc:creator>
      <dc:date>2021-01-25T20:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Introducing Deployment Server Stops Data Getting In</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/537159#M90036</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230681"&gt;@achauhan2098&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 07:36:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Introducing-Deployment-Server-Stops-Data-Getting-In/m-p/537159#M90036</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-26T07:36:31Z</dc:date>
    </item>
  </channel>
</rss>

