First of all, sorry for my english.
When Splunk deployment server (6.1.4 version) updates apps on deployment clients also update excluded files. I've defined excluding in serverclass.conf app stanza:
[serverClass:Linux:app:Splunk_TA_nix] restartSplunkWeb = 0 restartSplunkd = 0 stateOnClient = enabled excludeFromUpdate = $app_root$/local
If I added it to global section, also not working (also rewrite local directory,). Please help.
nope, found the issue. excludeFromUpdate only seems to work with 6.2 or higher clients. I thought this could be implemented on FW Management serverside.
I've implemented this and your syntax looks correct. It does look like your version is incompatible.
I don't think $app_root$ is a valid variable ... however you can define it inside your $SPLUNK_HOME/etc/splunk-launch.conf ;
Se here for more details;
I havent tested this, but $app_root$ should be substituted for the app name and trailed with the '/'
excludeFromUpdate = Splunk_TA_nix/local/
Try that and see if you receive any errors.
Thanks for your anwser, but still not working (override the local directory). There isnt relevant information in log files.