Deployment Architecture

clients with apps preloaded initally offline sync with deployment server later

Mag2sub
Path Finder

1 if we preload some apps into splunk in a offline manner and later sync it up into a deployment server with very same apps ...how do the apps behave ...on what basis is the checksum compared ?..what is this checksum ..and if checksum differs which overwrites what ?

2 if we cannot avoid the above scenario what is the best way to preserve the apps on the client ?

Tags (1)
0 Karma

lukejadamec
Super Champion

The App on the Client and the App on the Server must have the same checksum.

For each App Name, the Splunkd service on the Client will create a checksum of the entire App Folder on the client, and it will compare that checksum to the published checksum that was generated by the Splunkd service on the Server, if they do not match then the entire App folder will be downloaded. Deployed Apps are downloaded entire folder or nothing.

If you don't want an App to be controlled by the Deployment Server, then Never deploy an App with the same name.

Mag2sub
Path Finder

I guess i would really like to know what is this checksum calculation..is it a md5sum ? or what exactly entails a checksum match ?...appreciate ..as i keep seeing this word on online docs and wiki for deployment server

0 Karma

kristian_kolb
Ultra Champion
  1. You can preload an app. If you then create the 'same' app on a DS and push it out the client it will overwrite it. (or at least what is in the 'default' folders.). The client can not overwrite an app on the DS. How the checksum is calculated, I don't know - perhaps a MD5 of the files combined with mod_times??

  2. The best way is to not deploy an app with the same name (i.e. the name of the directory under SPLUNK_HOME/etc/deployment-apps on the DS).

However, things might have changed between versions, so start with a test environment and see what happens.

/k

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...