Getting Data In

Splunk server Vs Windows agent

kpsnathan_splun
New Member

Hello,

Splunk server in linux and agent in windows.

1)How to check from client or server cofig files ?
2)I created the deploymentclient.conf file under c:\program file\splunk\etc\system\local.
and restarted spulnkd service. Any services need to be restarted along with this...?

Please reply me as soon as possible.

Thanks,
Swami....

Tags (1)
0 Karma

lguinn2
Legend

From the deployment server, you can see which clients have connected:

./splunk list deploy-clients

On the deployment client, you can do

cd c:program files\splunk\bin
splunk display deploy-server

Some other questions (which may not be as relevant):

  • Are other deployment clients working? If no, then your problem might be on the deployment server, not the client...
  • Are you just setting up the deployment server? Try restarting it.
  • Have you reloaded the deployment server since you added new content? ./splunk reload deploy-server

Finally, I have found this search (or some variation) to be helpful

index="_internal" sourcetype="splunkd" component="DeploymentMetrics" | rename scName as serverClass fqname as install_location hostname as deploymentClient | table _time deploymentClient ip serverClass appName event status reason install_location
0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...