Getting Data In

Can refresh method push new apps from DS ServerClass to universal forwarder in AWS environment?

theouhuios
Motivator

We have a large AWS Environment and I want to try if we can refresh the UF to get the apps mentioned for it the DS Serverclass without a restart. If so, how is it possible? Is restart the only way to deploy new apps and start collecting the data?

0 Karma

starcher
Influencer

You do not push from DS. You update your app and do a reload deploy-server. That makes the update available to the UFs next time they check in and they pull the app if the checksum does not match indicating they need the new app. If you are involving changes to inputs.conf then in a lot of cases you do need to allow restart splunkd in the serverclass.conf stanza. Usually such auto restart is not an issue.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...