<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search Head clustering in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595109#M12368</link>
    <description>&lt;P&gt;but how do you distribute ? can give me some step by step process&lt;/P&gt;&lt;P&gt;in search head clustering to&amp;nbsp;search head clustering member.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Apr 2022 06:35:07 GMT</pubDate>
    <dc:creator>super_saiyan</dc:creator>
    <dc:date>2022-04-25T06:35:07Z</dc:date>
    <item>
      <title>How to distribute the default app, if I want to do some changes to the default app to the SHC members?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595090#M12366</link>
      <description>&lt;P&gt;how to distribute the default app, i&lt;SPAN&gt;f I want to do some changes&amp;nbsp; to the default app to the SHC members ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 15:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595090#M12366</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-04-25T15:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595095#M12367</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244498"&gt;@super_saiyan&lt;/a&gt;&amp;nbsp;- It is not recommended to make changes to default apps. Specifically for the SHC environment. I would always avoid it.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;You can create a custom App, and put your configuration, dashboard, alert, etc in that instead.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Is there any specific requirement to make changes to the default App? In most cases, you should be able to apply the above resolution.&lt;/P&gt;&lt;P&gt;------&lt;BR /&gt;I hope this helps!!!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 05:23:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595095#M12367</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-04-25T05:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595109#M12368</link>
      <description>&lt;P&gt;but how do you distribute ? can give me some step by step process&lt;/P&gt;&lt;P&gt;in search head clustering to&amp;nbsp;search head clustering member.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 06:35:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595109#M12368</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-04-25T06:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595122#M12369</link>
      <description>&lt;P&gt;Please read this documentation section &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/DistSearch/HowconfigurationworksinSHC" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/DistSearch/HowconfigurationworksinSHC&lt;/A&gt; especially this document &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.6/DistSearch/PropagateSHCconfigurationchanges" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.6/DistSearch/PropagateSHCconfigurationchanges&lt;/A&gt;&lt;/P&gt;&lt;P&gt;There is quite a lot going on with using deployer on SHC so it's important that you understand it.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 07:29:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595122#M12369</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-04-25T07:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595123#M12370</link>
      <description>&lt;P&gt;&lt;SPAN&gt;is it possible to distribute from Deployer of the default app ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 07:34:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595123#M12370</guid>
      <dc:creator>super_saiyan</dc:creator>
      <dc:date>2022-04-25T07:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Search Head clustering</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595138#M12371</link>
      <description>&lt;P&gt;It's strongly guided to really don't do it, as this normally leads unusable SHC cluster default app and probably also some other issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As other already said, please create your own "Default" app where users should create their KO's etc. and then deploy to it as needed. Even better is create several Apps for them based on your business systems etc. Give to those access by roles and you will get better granularity for security and access to those KOs.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2022 09:06:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-distribute-the-default-app-if-I-want-to-do-some-changes/m-p/595138#M12371</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-04-25T09:06:29Z</dc:date>
    </item>
  </channel>
</rss>

