Deployment Architecture

Deployment server - deleting apps- determine on client which apps have EVER been managed

robf
Path Finder

How can i determine if an app has ever been managed or is being managed?

I added a deploymentclient.conf to a dev HWF server and created serverclass etc on DS with only one test app. The deployment server only had one test app to push out and i assumed none of the other apps have ever been managed. They have definitely not been managed by this DS.

Anyhow, the Deployment server deleted about 20 apps....!!!!

I presume they were managed for a short time by someone else doing some testing, a long time ago?!

How can i found out if the apps have a history of being managed!? is there a log file or conf file somewhere? there must be!

http://docs.splunk.com/Documentation/Splunk/4.3.6/Deploy/Updateconfigurations#App_management_issues

😞

NOBODY KNOWS!!??

0 Karma

dstaulcu
Builder

on a client, you may be able to find copies of previously managed instances of apps in ./var/run folder.

depending on how quickly your logs rotate, you should also be able to review ./var/log/splunk/splunkd.log on both deployment-client and deployment-server logs for evidence of changes in deployed apps over time. on the splunk deployment server, you should also be able to look at internal access logs for who made changes over time.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...