Splunk Enterprise

Splunk Forwarder Restart Requirements when Deployed Apps are updated

shocko
Contributor

I'm using Splunk Enterprise 9.x  with Universal Forwarders 9.x on Windows 2019. All my forwarders are connected to a deployment server. I notice the following for example:

  1. I update a deployment server app (say update inputs.conf with a new input stanza)
  2. I restart the deployment server
  3. I view the inputs at the forwarder using btool and see that my changes have propagated

However, even though the updated inputs.conf file seems to have landed at the forwarder I do not see the events defined by my new inputs.conf hitting the indexer until I restart the forwarder. Perhaps this is expected based on this When to restart Splunk Enterprise after a configuration file change - Splunk Documentation ?

Is this expected and if so is there any way to restart the forwarder remotely using Splunk itself? 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Any app containing inputs.conf should have the "Restart splunkd" option enabled.  Do that in the Forwarder Management section of the Deployment Server.  That will tell the UF to restart itself each time it gets an updated copy of the app.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Any app containing inputs.conf should have the "Restart splunkd" option enabled.  Do that in the Forwarder Management section of the Deployment Server.  That will tell the UF to restart itself each time it gets an updated copy of the app.

---
If this reply helps you, Karma would be appreciated.

shocko
Contributor

I assumed (rather embarrassingly!) this restarted the deployment server splunkd! This is very useful. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
It’s not restarting Splunkd, it just reload deployment server DS related configurations. For that reason it’s much faster than restarting splunkd.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

just like @richgalloway said. One comment about your "restart ds". It's not needed to restart it, just reload it's configuration for deployment part with command 

splunk reload deploy-server

Or even add more granularity there it you have lot of configurations and restart or even base reload take too long.

r. Ismo 

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...