Deployment Architecture

Deployment Server and deployment apps issue.

splunktrainingu
Communicator

I am having issues with my deployment app config files. Whenever I edit the config file for my applications in my deployment apps and save it it doesn't replicate to those deployment clients. From my understanding the clients check their md5 hash of the apps in their folder and the server compares then pushes the new config files. I am not seeing any of my changes propagate because I know that I edited the config file and added event ID 4776 to be blacklisted and I can see it in my search results.

How do I fix this?

Labels (2)
Tags (1)
0 Karma
1 Solution

splunktrainingu
Communicator

Silly me, so under forwarder management you have to go to the apps tab and check the splunkd restart box and this fixed the the problem.

View solution in original post

0 Karma

splunktrainingu
Communicator

Silly me, so under forwarder management you have to go to the apps tab and check the splunkd restart box and this fixed the the problem.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...