Deployment Architecture

New inputs.conf Settings Not Applied After Pushing Configurations from Deployment Server (Splunk 9.2.1)

refahiati
Explorer

Hi Splunk community,

 

I'm facing an issue with my Splunk deployment server, running on version 9.2.1 (splunk-9.2.1-78803f08aabb-linux-2.6-x86_64-manifest). I’ve added new configurations to the inputs.conf file for a WebLogic server within a specific deployment class. After making these changes, I pushed the configurations to the target WebLogic server and triggered a restart.

Unfortunately, the new settings in the inputs.conf file are not being applied to the WebLogic server, even though the deployment server logs indicate that the service was successfully restarted.

Has anyone experienced this issue or can offer advice on what might be causing the problem and how to resolve it?

Thanks in advance!

Labels (2)
0 Karma

JohnEGones
Communicator

Hello refahiati,

Have you verified with a manual inspection of the conf files on the weblogic server that the desired changes were made? If so, restart the agent on the weblogic server again. Othrewise, revalidate that you deployed the configs correctly. Inspecting the splukd.log in var/log folder is also useful for gathering more details about what might be going wrong.

 

Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...