Deployment Architecture

Setting phoneHomeIntervalInSecs for deploymentclient.conf

gfriedmann
Communicator

I am having trouble getting the deploymentclient.conf setting phoneHomeIntervalInSecs to be followed.

Using a universal forwarder on windows the default checkin seems to be 60 seconds. I tried to specify 5 minutes in /apps/foo/local/deploymentclient.conf , but it still checks in every 60 seconds.

Does anyone know if this must be set in system/local/deploymentclient.conf or if it expected to work if specified in any /etc/app/foo/local/deploymentclient.conf ?

Tags (1)
0 Karma
1 Solution

Ellen
Splunk Employee
Splunk Employee

There is a known issue (SPL-41174) regarding phonehome messages incorrectly displaying at the default of every 60 seconds despite resetting phoneHomeIntervalInSecs.

See this for more details.

View solution in original post

Ellen
Splunk Employee
Splunk Employee

There is a known issue (SPL-41174) regarding phonehome messages incorrectly displaying at the default of every 60 seconds despite resetting phoneHomeIntervalInSecs.

See this for more details.

gkanapathy
Splunk Employee
Splunk Employee

It has always worked for me in an app folder.

0 Karma

gfriedmann
Communicator

How did you verify the checkin interval?

0 Karma

hazekamp
Builder

This could be caused by a permissions issue in your apps/foo/metadata/default.meta. Try adding:

## default.meta
[deploymentclient]
export = system

jbsplunk
Splunk Employee
Splunk Employee

I've seen other similar issues fixed by using this setting.

0 Karma

gfriedmann
Communicator

I will try.

0 Karma

gfriedmann
Communicator

I can use the same syntax to override the setting in system/local/deploymentclient.conf and it works as expected.

but in apps/foo/local/deploymentclient.conf , it still shows up as desired when i type "splunk show config -name deploymentclient", but the checkins continue at 60 second intervals.

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...