Splunk® Enterprise

Updating Splunk Enterprise Instances

Splunk Enterprise version 8.0 is no longer supported as of October 22, 2021. See the Splunk Software Support Policy for details. For information about upgrading to a supported version, see How to upgrade Splunk Enterprise.

Deploy apps to clients

The deployment server distributes deployment apps to clients.

It deploys apps at these times:

  • When you create a server class and map a set of clients to one or more apps.
  • When you change a server class (for example, by changing its set of apps or clients).
  • When you change the content of an app.
  • When a new client joins a server class.

In some cases, it deploys apps automatically. In other cases, you need to manually initiate the deployment. In part, this depends on whether you are using forwarder management or editing serverclass.conf directly.

For help estimating the time required to deploy apps, see Estimate deployment server performance.

Deploy apps to clients in a new or updated server class

After you create or change a server class, the next step is to deploy its apps to the clients qualified by its filters. If you configure the server class through forwarder management, this happens automatically. If you configure the server class by directly editing serverclass.conf, you must manually initiate the deployment.

When using forwarder management

When you first create a server class, you map a set of clients to a set of apps. After you specify both the client filters and the apps, the deployment server automatically deploys the apps to the qualifying clients. This process is described in Use forwarder management to define server classes.

When you later edit a server class, changing either its set of apps or its client filters, the deployment server redeploys all server classes. That is, if the content of any app in any server class (not only in the server class you just edited) has changed since it was last deployed, the deployment server now deploys the latest version to the qualifying clients.

Whenever you use forwarder management to change a configuration, it automatically reloads the deployment server. This causes the deployment server to redeploy any changed apps across all server classes.

When editing serverclass.conf directly

You can create server classes by directly editing serverclass.conf. The deployment server does not automatically deploy apps in response to direct edits of serverclass.conf, unlike when you edit through forwarder management. Instead, you must manually reload the deployment server to initiate deployments.

To reload, invoke the CLI reload deploy-server command:

 splunk reload deploy-server

After you run reload deploy-server, the deployment server deploys all server classes. That is, if any app in any server class is new or has changed since it was last deployed, the deployment server deploys the latest version to the qualifying clients for that server class. Similarly, if you have edited a client filter since the last time you reloaded the deployment server, the deployment server ensures, for each server class, that all the currently qualifying clients get the latest set of apps.

For information on creating server classes by directly editing serverclass.conf, see Use serverclass.conf to define server classes.

Redeploy an app after you change its content

When you update the content of an app, you must reload the deployment server in order for the deployment server to redeploy the app.

If you are using forwarder management, you must also manually reload the deployment server if you want to redeploy the app immediately. However, if you do not manually reload the deployment server, the app will still get redeployed once you make ''any'' subsequent configuration changes in forwarder management.

To redeploy an app with updated content:

1. Update the content in the relevant deployment app directory on the deployment server.

2. Reload the deployment server to make the deployment server aware of the changed content.

The deployment server then redeploys the app to all clients that it's mapped to.

1. Update the content

The topic Create deployment apps described how to create app directories on the deployment server. You can add or overwrite the content in those directories at any time.

2. Reload the deployment server

After you edit the content of an app, you must reload the deployment server so that the deployment server learns of the changed app. It then redeploys the app to the mapped set of clients.

To reload the deployment server, use the CLI reload deploy-server command:

 splunk reload deploy-server

The command checks all apps for changes and notifies the relevant clients.

Deploy apps to a new client

When a deployment client connects with the deployment server for the first time, the deployment server automatically deploys the apps for any server classes that it qualifies for. You do not need to reload the deployment server in this instance.

An example of this is when you configure a new deployment client, and that client has a machine type that an existing server class filters for.

Last modified on 09 December, 2024
Set up client filters   Protect content during app updates

This documentation applies to the following versions of Splunk® Enterprise: 7.0.0, 7.0.1, 7.0.2, 7.0.3, 7.0.4, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.13, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.1.10, 8.1.11, 8.1.12, 8.1.13, 8.1.14, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.2.5, 8.2.6, 8.2.7, 8.2.8, 8.2.9, 8.2.10, 8.2.11, 8.2.12, 9.0.0, 9.0.1, 9.0.2, 9.0.3, 9.0.4, 9.0.5, 9.0.6, 9.0.7, 9.0.8, 9.0.9, 9.0.10, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5, 9.1.6, 9.1.7, 9.2.0, 9.2.1, 9.2.2, 9.2.3, 9.2.4, 9.3.0, 9.3.1, 9.3.2, 9.4.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters