<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deployment applications in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695601#M14110</link>
    <description>&lt;P&gt;Is the client set to restart itself when it downloads the app?&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2024 19:04:11 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-08-07T19:04:11Z</dc:date>
    <item>
      <title>Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695595#M14109</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I have a problem with Deployment Server. I would like to setup e-mail settings for all my Splunk servers using Deployment application. I have created Deployment server, I have created classess and applicatoins I want to deploy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Application is downloading to right servers. Application is very simple. I had created file "/opt/splunk/etc/deployment-apps/setSplunkCommonConfig/default/xxx_alert.actions.conf" with following content:&lt;/P&gt;&lt;P&gt;[email]&lt;BR /&gt;allowedDomainList = domain.com&lt;BR /&gt;pdf.header_left = none&lt;BR /&gt;pdf.header_right = none&lt;/P&gt;&lt;P&gt;This application is downloaded to client and it is stored under "/opt/splunk/etc/apps/setSplunkCommonConfig" directory and file "xxx_alert.actions.conf" is there.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So distribution of aplication looks working fine. But there I have problem that settings from file "xxx_alert.actions.conf" are not applied on client.&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;Deploy server can copy files to which directories "/opt/splunk/etc/system/local" or "/opt/splunk/etc/system/default" or both?&lt;/P&gt;&lt;P&gt;Than you for any hint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 18:24:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695595#M14109</guid>
      <dc:creator>Cievo</dc:creator>
      <dc:date>2024-08-07T18:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695601#M14110</link>
      <description>&lt;P&gt;Is the client set to restart itself when it downloads the app?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 19:04:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695601#M14110</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-08-07T19:04:11Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695602#M14111</link>
      <description>&lt;P&gt;Nope. Is it neccesary to restart splunkd?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 19:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695602#M14111</guid>
      <dc:creator>Cievo</dc:creator>
      <dc:date>2024-08-07T19:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695603#M14112</link>
      <description>&lt;P&gt;Restart didn't help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 19:10:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695603#M14112</guid>
      <dc:creator>Cievo</dc:creator>
      <dc:date>2024-08-07T19:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695611#M14113</link>
      <description>&lt;P&gt;I wanted to change "Allowed Domains" field under Server Settings -&amp;gt; Email settings.&lt;/P&gt;&lt;P&gt;When I do it using website I get following log in audit.log:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"changes":[{"stanza":"email","properties":[{"name":"allowedDomainList","new_value":"domain1.sk","old_value":""},&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;When new application is installed I can see following log line saying that value is changing:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"changes":[{"stanza":"email","properties":[{"name":"allowedDomainList","new_value":"domain2.sk","old_value":""},&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;But difference is, that if value is changed using deployment application, I don't see accurate change on website - Allowed Domains is empty.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would you do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 20:17:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695611#M14113</guid>
      <dc:creator>Cievo</dc:creator>
      <dc:date>2024-08-07T20:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695733#M14118</link>
      <description>&lt;P&gt;Login to any of those servers and use&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;splunk btool alert_actions list --debug&lt;/LI-CODE&gt;&lt;P&gt;In this way you see from which file each setting is coming.&lt;/P&gt;&lt;P&gt;I’m not sure, but there could be some settings in this config which are working only from …/system/local or at least that was case on older versions (6.x and 7.x)?&lt;BR /&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 17:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695733#M14118</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-08-08T17:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695740#M14119</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Thank you for your answer. I tried your command and I have got:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;root@MSVMSLMCLM01:/opt/splunk/bin# ./splunk btool alert_actions list --debug | grep allowed&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;/opt/splunk/etc/apps/setSplunkCommonConfig/default/alert_actions.conf allowedDomainList = domain.sk&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;root@MSVMSLMCLM01:/opt/splunk/bin# ./splunk btool alert_actions list --debug | grep from&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;/opt/splunk/etc/apps/setSplunkCommonConfig/default/alert_actions.conf from = &lt;A href="mailto:splunk@domain.sk" target="_blank"&gt;splunk@domain.sk&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;So this looks like settings are used from correct file, file from pushed application. But when I check web on this machine, those values are empty:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cievo_0-1723139827896.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32114i9EA36974C5E226B1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cievo_0-1723139827896.png" alt="Cievo_0-1723139827896.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 17:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695740#M14119</guid>
      <dc:creator>Cievo</dc:creator>
      <dc:date>2024-08-08T17:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695752#M14120</link>
      <description>Are you running splunk as root or some other user? Use root is against security practices!&lt;BR /&gt;If you are running it as splunk, you should also check btool with that user. Otherwise there is small possibility that those files are owned by root and splunk user haven’t read access to those.&lt;BR /&gt;Another option is that some options can set only in …/system/local. Unfortunately you cannot use DS to deploy those configuration into it.&lt;BR /&gt;Maybe it’s best to rise Spunk support case for it!</description>
      <pubDate>Thu, 08 Aug 2024 19:25:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695752#M14120</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-08-08T19:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment applications</title>
      <link>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695983#M14132</link>
      <description>&lt;P&gt;You are absolutely right. Splunk ran under root account. I have changed it already, but it didn't help.&lt;/P&gt;&lt;P&gt;Normal universal forwarders works great, only Splunk servers don't change configuration. But I will handle it using ../local/ files as you suggested.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 11:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Deployment-applications/m-p/695983#M14132</guid>
      <dc:creator>Cievo</dc:creator>
      <dc:date>2024-08-12T11:40:15Z</dc:date>
    </item>
  </channel>
</rss>

