<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk_TA_Windows deployment on a Search Head in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652068#M79515</link>
    <description>&lt;P&gt;Hi, we have a distributed Splunk environment and I have successfully deployed the UF to Windows Server. I am getting data into my Indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is regarding the Search Head cluster. I believe I need to deploy the TA also to the Search Heads to get properties from the props.conf and other files.&lt;/P&gt;&lt;P&gt;Do I need to deploy the complete TA to my Search heads or just specific files?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Alex&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jul 2023 14:20:32 GMT</pubDate>
    <dc:creator>dersa</dc:creator>
    <dc:date>2023-07-26T14:20:32Z</dc:date>
    <item>
      <title>Splunk_TA_Windows deployment on a Search Head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652068#M79515</link>
      <description>&lt;P&gt;Hi, we have a distributed Splunk environment and I have successfully deployed the UF to Windows Server. I am getting data into my Indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is regarding the Search Head cluster. I believe I need to deploy the TA also to the Search Heads to get properties from the props.conf and other files.&lt;/P&gt;&lt;P&gt;Do I need to deploy the complete TA to my Search heads or just specific files?&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Alex&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652068#M79515</guid>
      <dc:creator>dersa</dc:creator>
      <dc:date>2023-07-26T14:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_Windows deployment on a Search Head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652073#M79516</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can install Splunk_TA_Windows on search head by removing the inputs.conf file for managing KOs &amp;amp; other Search time functionalities.&lt;/P&gt;&lt;P&gt;Refer the below documentation:&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Windows/Install#Distributed_deployment_feature_compatibility" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/AddOns/released/Windows/Install#Distributed_deployment_feature_compatibility&lt;/A&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P class=""&gt;&lt;SPAN&gt;You can install this add-on on a search head cluster for all search-time functionality, but configure inputs on forwarders to avoid duplicate data collection.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Before you install this add-on to a cluster, make the following changes to the add-on package: Remove the&amp;nbsp;&lt;/SPAN&gt;inputs.conf&lt;SPAN&gt;&amp;nbsp;file.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:40:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652073#M79516</guid>
      <dc:creator>nniranjanreddy</dc:creator>
      <dc:date>2023-07-26T14:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_Windows deployment on a Search Head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652075#M79517</link>
      <description>&lt;P&gt;Thanks for the quick reply. I'll give it a try right now.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652075#M79517</guid>
      <dc:creator>dersa</dc:creator>
      <dc:date>2023-07-26T14:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_Windows deployment on a Search Head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652076#M79518</link>
      <description>&lt;P&gt;Deploy the complete TA with inputs disabled to your SH.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:47:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652076#M79518</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-26T14:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk_TA_Windows deployment on a Search Head</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652086#M79519</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/84285"&gt;@dersa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I'm agree with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;: I don't like to customize add-ons, I always prefer to use standard add-ons, eventually disabling inputs, to avoid, for the updates, to remember the customizations you did and make them every time.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 15:29:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-TA-Windows-deployment-on-a-Search-Head/m-p/652086#M79519</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-26T15:29:47Z</dc:date>
    </item>
  </channel>
</rss>

