Splunk Enterprise

What happens when deployment server goes down/is not UP?

Ashwini008
Builder

Hi,

Could you please explain me what happens when deployment server stops working? How does it affects data inflow from UF's? and what components can be affected if DS goes down.

 

Thank You

0 Karma

PickleRick
SplunkTrust
SplunkTrust

The DS does not connect actively to deployment clients (forwarders) and on its own it does not enforce anything. So whether DS is up or down does not have any impact on the immediate operations of the forwarders.

It's just that the deployment clients periodically connect to the DS and "ask" it whether there is an updated configuration bundle for them and if there is one, they pull one from DS and apply it.

So if the DS is not available the forwarder is simply not able to "call home" and ask for new config bundle.

It does not stop the forwarder or anything like that. You simply can't distribute new config to clients but nothing else should happen.

Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...