Getting Data In

Deployment server app inputs.conf vs Forwarder inputs.conf

rchittip
Path Finder

I have updated an app inputs.conf (/opt/splunk/splunkforwarder/etc/apps/inputs_prod/local) in one of my Universal Forwarder agent and added one extra input stanza. Basically this app is pushed to Universal forwarder from Deployment server.

The inputs.conf on deployment server for this app remains same and there were no changes made.

What if the case, if I reload the deployment server does it push the same old inputs.conf to this app to the server ?

Can someone explain me this. Thanks.

Tags (1)
0 Karma
1 Solution

mdsnmss
SplunkTrust
SplunkTrust

I just tested this with a couple different changes. If you make changes to the inputs locally on the forwarder and then it will retain the changes on the UF after a reload deploy-server whether or not the changes are made in the local or default directory of that app.

The issue will come if you update the app on the deployment server. If you update the app at anytime on the deployment server then the changes on the UF will be wiped out regardless of if they are in the local or default directory.

I'd recommend updating the app on the deployment server or creating a new app and server class to include the new stanza for the client you would like to update.

View solution in original post

0 Karma

mdsnmss
SplunkTrust
SplunkTrust

I just tested this with a couple different changes. If you make changes to the inputs locally on the forwarder and then it will retain the changes on the UF after a reload deploy-server whether or not the changes are made in the local or default directory of that app.

The issue will come if you update the app on the deployment server. If you update the app at anytime on the deployment server then the changes on the UF will be wiped out regardless of if they are in the local or default directory.

I'd recommend updating the app on the deployment server or creating a new app and server class to include the new stanza for the client you would like to update.

0 Karma

FrankVl
Ultra Champion

I think it will revert to the DS version already upon the first next handshake between forwarder and DS, not only after a reload.

If an app is deployed from DS, you should edit it there and then push it out.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...