Deployment Architecture

Setting phoneHomeIntervalInSecs for deploymentclient.conf

gfriedmann
Communicator

I am having trouble getting the deploymentclient.conf setting phoneHomeIntervalInSecs to be followed.

Using a universal forwarder on windows the default checkin seems to be 60 seconds. I tried to specify 5 minutes in /apps/foo/local/deploymentclient.conf , but it still checks in every 60 seconds.

Does anyone know if this must be set in system/local/deploymentclient.conf or if it expected to work if specified in any /etc/app/foo/local/deploymentclient.conf ?

Tags (1)
0 Karma
1 Solution

Ellen
Splunk Employee
Splunk Employee

There is a known issue (SPL-41174) regarding phonehome messages incorrectly displaying at the default of every 60 seconds despite resetting phoneHomeIntervalInSecs.

See this for more details.

View solution in original post

Ellen
Splunk Employee
Splunk Employee

There is a known issue (SPL-41174) regarding phonehome messages incorrectly displaying at the default of every 60 seconds despite resetting phoneHomeIntervalInSecs.

See this for more details.

gkanapathy
Splunk Employee
Splunk Employee

It has always worked for me in an app folder.

0 Karma

gfriedmann
Communicator

How did you verify the checkin interval?

0 Karma

hazekamp
Builder

This could be caused by a permissions issue in your apps/foo/metadata/default.meta. Try adding:

## default.meta
[deploymentclient]
export = system

jbsplunk
Splunk Employee
Splunk Employee

I've seen other similar issues fixed by using this setting.

0 Karma

gfriedmann
Communicator

I will try.

0 Karma

gfriedmann
Communicator

I can use the same syntax to override the setting in system/local/deploymentclient.conf and it works as expected.

but in apps/foo/local/deploymentclient.conf , it still shows up as desired when i type "splunk show config -name deploymentclient", but the checkins continue at 60 second intervals.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...