Deployment Architecture

server.conf in app

dvg06
Path Finder

hi Experts,

Can I put server.conf file within an application, and use deployment server to push it to forwarders?

Regards,
Dinesh

Tags (1)
0 Karma
1 Solution

adonio
Ultra Champion

yes you can, its being used many times, for example, deploy the license master configuration for non clustered indexers
server.conf in an app

  [license]
    master_uri = https://10.2.1.3:8089

which configurations in server.conf are you thinking of deploying to the forwarders?

View solution in original post

0 Karma

dvg06
Path Finder

Due to some unknown reason, splunk is accepting etc/system parameters only, not the parameters which I put in app-context.

[splunk@ip-10-0-1-11 etc]$ more /opt/splunkforwarder/etc/apps/itoa-monitoring-data/default/server.conf
[general]
serverName=100.200.200.200
[splunk@ip-10-0-1-11 etc]$ /opt/splunkforwarder/bin/splunk cmd btool server list --debug | grep serverName
Warning: overriding $SPLUNK_HOME setting in environment ("/opt/splunk") with "/opt/splunkforwarder". If this is not correct, edit /opt/splunkforwarder/etc/splunk-launch.conf
/opt/splunkforwarder/etc/system/local/server.conf serverName = 100.100.100.100
[splunk@ip-10-0-1-11 etc]$

0 Karma

adonio
Ultra Champion

take a look at splunk file precedence order:
http://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Wheretofindtheconfigurationfiles#Precedence_...
.../etc/system/local takes precedence over .../etc/apps/app/local
hope it clears it

dvg06
Path Finder

thank you. all good now.

0 Karma

adonio
Ultra Champion

yes you can, its being used many times, for example, deploy the license master configuration for non clustered indexers
server.conf in an app

  [license]
    master_uri = https://10.2.1.3:8089

which configurations in server.conf are you thinking of deploying to the forwarders?

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...