Deployment Architecture

It takes a very long time to deploy an app using deploy server

las
Contributor

Hello.

I have around 450 universal forwarders connected to one deployment server, all the host are windows, some 2008 others 2003, I have phonehome set to 900 secs. so I should get a phonecall around 4 times an hour.

I made an app, that is destined for all the servers, after about 22 hours my app is still not distributed to around 90 servers. The process has not stopped, so the number goes down very slowly, but the app gets distributed still.

My Universal forwarders are 5.0.1, and my deployment server is 5.0.4.

Is it normal with such large latency in the deployment process?

Kind regards
las

1 Solution

lukejadamec
Super Champion

Check out this document. Inside you will find troubleshooting ideas, and a recommendation that for your environment you should have multiple deployment servers.

http://wiki.splunk.com/Deploy:DeploymentServer

View solution in original post

lukejadamec
Super Champion

Check out this document. Inside you will find troubleshooting ideas, and a recommendation that for your environment you should have multiple deployment servers.

http://wiki.splunk.com/Deploy:DeploymentServer

las
Contributor

ok, thanks.
I'll try to see how to make this work, as the current config is in system/local, so that might be a challenge.
Again thanks

0 Karma

lukejadamec
Super Champion

I just looked into that, and I don't believe it is. What you can do is have a primary and secondary deployment server. The secondary is a client of the primary, and the clients get apps from either the primary or secondary.

0 Karma

las
Contributor

Just a follow up.
Is it possible to define two deploymentservers for one deploymentclient?

0 Karma

las
Contributor

Yes, but the server is not under any form of stress.
Neither from network, CPU or RAM.

0 Karma

lukejadamec
Super Champion

Is the deployment server also an indexer?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...