Deployment Architecture

List deployment client showing "no clients contacted the server"

Poojitha
Path Finder

Hi,

I have set up deployment server. When I checked splunkd_access.log , it shows successful phonehome connection from Heavy Forwarder. I can also see app getting deployed in  deployment clients.

But when I do ./splunk list deploy-clients, it is showing "No deployment clients have contacted this server".

What is going wrong here ? Please can anyone of you help me.

Regards,
PNV

Labels (2)
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Poojitha
Path Finder

Thanks @isoutamo  Thank you. Now I see the deployment clients are being listed using the command .
./splunk list deploy-clients.

I added the stanza under /opt/splunk/etc/system/local/outputs.conf following the link you posted.

[indexAndForward]
index = true
selectiveIndexing = true



Thanks again 🙂

Regards,
PNV

Poojitha
Path Finder

@isoutamo  : Thanks for the links you provided.

I see that my old DS lists all clients contacting. It is running 9.0.2. Where as the new one which I am trying to setup is running 9.2.1. I see from the links that, it is because of the version difference.

However , I tried the steps provided in the link. Still no luck. 

I also should mention that I am configuring this DS to act as log forwarder as well. So, it is that both of these setup is making use of same splunk service. Does this have any effect on proper working of Deployment Server.
Do you have any comments ? Apart from the steps in above link , do you have any other suggestion.

Thanks in Advance,
PNV

Regards,
PNV

0 Karma

isoutamo
SplunkTrust
SplunkTrust
If I have understand right this is doable also on IHF + DS combination, but it could be tricky as those functions are different. Also if you have more than 50 client then you should/must have a separate DS server for those.

Since 9.2.x DS server expects that there are some local indexes where it stores information about DS actions. If you haven't those or you are sending all events into your real indexers then this didn't work.

If I recall right there are some instructions how this can do, but I prefer that you will install one new dedicated server for DS and use those local indexes for DS function. That way it will be much easier to get it to work.

Other option is look from community, docs and Splunk usergroup Slack how this can do in combined IHF + DS. It needs some additional tuning for outputs.conf at least, maybe it was some other conf files too?
0 Karma

splunkreal
Motivator

Hello @Poojitha  you can try splunk list deploy-clients -count -1

Also you should use Settings/Forwarder management (GUI interface of your DMC server).

 

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

Poojitha
Path Finder

@splunkreal  : Thanks .. I tried the command but no luck 😞 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...