Deployment Architecture

Why does authorize.conf reside on the default directory of the search head?

ddrillic
Ultra Champion

On the deployer server we have the authorize.conf under /opt/splunk/etc/shcluster/apps/key_all_authentication/local. On the SH it ends up at /opt/splunk/etc/apps/key_all_authentication/default. Why under default?

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @ddrillic,

Please refer this https://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/PropagateSHCconfigurationchanges#App_c... , when deployer push app configuration it merge both local and default directory and place the configuration in default directory on Cluster Member.

I hope this helps.

Thanks,
Harshil

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi @ddrillic,

Please refer this https://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/PropagateSHCconfigurationchanges#App_c... , when deployer push app configuration it merge both local and default directory and place the configuration in default directory on Cluster Member.

I hope this helps.

Thanks,
Harshil

0 Karma

ddrillic
Ultra Champion

Gorgeous @harsmarvania57 !!!

It says -

-- When it deploys apps, the deployer places the app configurations in default directories on the cluster members.

-- The deployer never deploys files to the members' local app directories, $SPLUNK_HOME/etc/apps/<app_name>/local. Instead, it deploys both local and default settings from the configuration bundle to the members' default app directories, $SPLUNK_HOME/etc/apps/<app_name>/default. This ensures that deployed settings never overwrite local or replicated runtime settings on the members. Otherwise, for example, app upgrades would wipe out runtime changes.

0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

&#x1f5e3; You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...