Deployment Architecture

Deployment Server

hectorvp
Communicator

I have Linux box as deployment server and windows servers where UF is hosted.

I'm able to successfully deploy application from deployment server to UF. However, I'm not able to fetch logs in my indexer.

In deployment server configurations are located at -> 

/opt/splunk/etc/deployment-apps/windows_app/default

"windows_database" is app name

In UF(windows) these conf get downloaded at ->

\etc\apps\windows_app\default

But I guess these configuration are not been take into effect to monitor logs,don't know why.

I copied same configuration (inputs.conf & outputs.conf) and pasted in -> \etc\system\local

And was able to fetch every logs as intended. Did I miss out something while trying to implement using deployment server???

Configuration files are :

inputs.conf ->

[default]

[WinEventLog://Security]
disabled = 0
index= main

[WinEventLog://Application]
disabled = 0
index = main

[WinEventLog://System]
disabled = 0
index = main

 

Outputs.conf ->

[tcpout]
defaultGroup=ath_indexers

[tcpout:ath_indexers]
server=18.185.116.9:9997

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @hectorvp,

probably I'm saying something that you already did:

a Technical add-Onn (TA) is structured as all the Splunk apps, at least the following folders:

  • default
  • local
  • metadata

In local or default folder you have to put your files (inputs.conf, props.con, etc...)

TAs must be located on Deployment Server in $SPLUNK_HOME/etc/deployment-apps as folders (not zip or tar or tgz).

Deployment server deployes TAs in $SPLUNK_HOME\apps (in Windows)

Remember, on Deployment Server, to flag "restart ufter updates" option (by default it isn't flagged) otherwise changes aren't activated.

For Windows logs, I hint to use the Splunk TA Windows (https://splunkbase.splunk.com/app/742/)  instead custom inputs, remembering to enable the stanzas you want.

Only one last question: searching for Splunk internal logs did you have results?

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hectorvp,

probably I'm saying something that you already did:

a Technical add-Onn (TA) is structured as all the Splunk apps, at least the following folders:

  • default
  • local
  • metadata

In local or default folder you have to put your files (inputs.conf, props.con, etc...)

TAs must be located on Deployment Server in $SPLUNK_HOME/etc/deployment-apps as folders (not zip or tar or tgz).

Deployment server deployes TAs in $SPLUNK_HOME\apps (in Windows)

Remember, on Deployment Server, to flag "restart ufter updates" option (by default it isn't flagged) otherwise changes aren't activated.

For Windows logs, I hint to use the Splunk TA Windows (https://splunkbase.splunk.com/app/742/)  instead custom inputs, remembering to enable the stanzas you want.

Only one last question: searching for Splunk internal logs did you have results?

Ciao.

Giuseppe

0 Karma

hectorvp
Communicator

Nope I didn't received any internal logs when configurations were inside apps.

When I pasted same configurations in etc\system\local....I fetched internal as well as windows event logs as intended.

Point to raise this question was this happened with me twice.May be I missing something.

Thanks for the suggestion to use  app "Splunk Add on for Windows".

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hectorvp,

if you don't receive interval logs from that server, it means that the problem isn't in inputs.conf but in outputs.conf or there's a network problem between UF and Indexer to debug.

if you try telnet from that server to the indexer what result do you have?

telnet ip_indexer 9997

 Ciao.

Giuseppe

hectorvp
Communicator

Thanks @gcusello,  

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...