Splunk Enterprise

What happens when deployment server goes down/is not UP?



Could you please explain me what happens when deployment server stops working? How does it affects data inflow from UF's? and what components can be affected if DS goes down.


Thank You

0 Karma

Ultra Champion

The DS does not connect actively to deployment clients (forwarders) and on its own it does not enforce anything. So whether DS is up or down does not have any impact on the immediate operations of the forwarders.

It's just that the deployment clients periodically connect to the DS and "ask" it whether there is an updated configuration bundle for them and if there is one, they pull one from DS and apply it.

So if the DS is not available the forwarder is simply not able to "call home" and ask for new config bundle.

It does not stop the forwarder or anything like that. You simply can't distribute new config to clients but nothing else should happen.

Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...