Splunk Enterprise

What happens when deployment server goes down/is not UP?



Could you please explain me what happens when deployment server stops working? How does it affects data inflow from UF's? and what components can be affected if DS goes down.


Thank You

0 Karma


The DS does not connect actively to deployment clients (forwarders) and on its own it does not enforce anything. So whether DS is up or down does not have any impact on the immediate operations of the forwarders.

It's just that the deployment clients periodically connect to the DS and "ask" it whether there is an updated configuration bundle for them and if there is one, they pull one from DS and apply it.

So if the DS is not available the forwarder is simply not able to "call home" and ask for new config bundle.

It does not stop the forwarder or anything like that. You simply can't distribute new config to clients but nothing else should happen.

Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...