Deployment Architecture

Why does authorize.conf reside on the default directory of the search head?

ddrillic
Ultra Champion

On the deployer server we have the authorize.conf under /opt/splunk/etc/shcluster/apps/key_all_authentication/local. On the SH it ends up at /opt/splunk/etc/apps/key_all_authentication/default. Why under default?

0 Karma
1 Solution

harsmarvania57
Ultra Champion

Hi @ddrillic,

Please refer this https://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/PropagateSHCconfigurationchanges#App_c... , when deployer push app configuration it merge both local and default directory and place the configuration in default directory on Cluster Member.

I hope this helps.

Thanks,
Harshil

View solution in original post

0 Karma

harsmarvania57
Ultra Champion

Hi @ddrillic,

Please refer this https://docs.splunk.com/Documentation/Splunk/7.0.0/DistSearch/PropagateSHCconfigurationchanges#App_c... , when deployer push app configuration it merge both local and default directory and place the configuration in default directory on Cluster Member.

I hope this helps.

Thanks,
Harshil

0 Karma

ddrillic
Ultra Champion

Gorgeous @harsmarvania57 !!!

It says -

-- When it deploys apps, the deployer places the app configurations in default directories on the cluster members.

-- The deployer never deploys files to the members' local app directories, $SPLUNK_HOME/etc/apps/<app_name>/local. Instead, it deploys both local and default settings from the configuration bundle to the members' default app directories, $SPLUNK_HOME/etc/apps/<app_name>/default. This ensures that deployed settings never overwrite local or replicated runtime settings on the members. Otherwise, for example, app upgrades would wipe out runtime changes.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...