Deployment Architecture

After deploying apps using the Deployment Server, does Splunk restart all of them at once?

aferone
Builder

We are just starting to use Deployment Server. Most of my apps are for inputs.conf and outputs.conf configurations. Normally, when editing both of these files in local, we need to restart the Splunk service.

If I deploy 2 inputs apps, and 1 outputs app, does Splunk restart 3 different times, since that's the setting for each app on the Deployment Server? Or does Splunk know to only restart once?

Thanks!

0 Karma
1 Solution

MuS
SplunkTrust
SplunkTrust

Hi aferone,

In theory Splunk will restart after each of the apps is deployed, but you could also just have one restart.

Another option to have more control about this, is to have no deployment apps configured to perform a restart. Instead use a dummy app which contains for example just a readme.txt, assign the restart Splunk option to this dummy app and use the Splunk UI to assign clients that need a restart to the dummy app. This way you can select the UF's that will be restarted and you know they will be restarted only once.

Hope this makes sense and helps ...

cheers, MuS

View solution in original post

MuS
SplunkTrust
SplunkTrust

Hi aferone,

In theory Splunk will restart after each of the apps is deployed, but you could also just have one restart.

Another option to have more control about this, is to have no deployment apps configured to perform a restart. Instead use a dummy app which contains for example just a readme.txt, assign the restart Splunk option to this dummy app and use the Splunk UI to assign clients that need a restart to the dummy app. This way you can select the UF's that will be restarted and you know they will be restarted only once.

Hope this makes sense and helps ...

cheers, MuS

aferone
Builder

Thanks! I'll try it!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...