Getting Data In

Deployment server app inputs.conf vs Forwarder inputs.conf

rchittip
Path Finder

I have updated an app inputs.conf (/opt/splunk/splunkforwarder/etc/apps/inputs_prod/local) in one of my Universal Forwarder agent and added one extra input stanza. Basically this app is pushed to Universal forwarder from Deployment server.

The inputs.conf on deployment server for this app remains same and there were no changes made.

What if the case, if I reload the deployment server does it push the same old inputs.conf to this app to the server ?

Can someone explain me this. Thanks.

Tags (1)
0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

I just tested this with a couple different changes. If you make changes to the inputs locally on the forwarder and then it will retain the changes on the UF after a reload deploy-server whether or not the changes are made in the local or default directory of that app.

The issue will come if you update the app on the deployment server. If you update the app at anytime on the deployment server then the changes on the UF will be wiped out regardless of if they are in the local or default directory.

I'd recommend updating the app on the deployment server or creating a new app and server class to include the new stanza for the client you would like to update.

View solution in original post

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

I just tested this with a couple different changes. If you make changes to the inputs locally on the forwarder and then it will retain the changes on the UF after a reload deploy-server whether or not the changes are made in the local or default directory of that app.

The issue will come if you update the app on the deployment server. If you update the app at anytime on the deployment server then the changes on the UF will be wiped out regardless of if they are in the local or default directory.

I'd recommend updating the app on the deployment server or creating a new app and server class to include the new stanza for the client you would like to update.

0 Karma

FrankVl
Ultra Champion

I think it will revert to the DS version already upon the first next handshake between forwarder and DS, not only after a reload.

If an app is deployed from DS, you should edit it there and then push it out.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...