<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Search head cluster dilemma -- Is there a way to reverse this configuration issue? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360514#M13307</link>
    <description>&lt;P&gt;If you use the GUI or the &lt;CODE&gt;Lookup File Editor&lt;/CODE&gt; app (&lt;A href="https://splunkbase.splunk.com/app/1724/"&gt;https://splunkbase.splunk.com/app/1724/&lt;/A&gt;), these changes will be synchronized across the cluster.  Do not use the Deployer for a simple Lookup File change.  You are risking big trouble if you do.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jul 2018 15:09:05 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2018-07-18T15:09:05Z</dc:date>
    <item>
      <title>Search head cluster dilemma -- Is there a way to reverse this configuration issue?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360508#M13301</link>
      <description>&lt;P&gt;hi everyone:&lt;/P&gt;

&lt;P&gt;I seem to have made a mistake on the cluster.  I wanted to add a lookup table in the lookups directory of search app (&lt;CODE&gt;$SPLUNK_HOME/etc/apps/search/lookups&lt;/CODE&gt; on everyone cluster member). In order to make all the search head (4 search head) have the same configuration. I did the following steps：&lt;/P&gt;

&lt;P&gt;Step 1: copy the search app of one of the search heads to deployer&lt;BR /&gt;
Step  2: then I added a lookup table in the &lt;CODE&gt;$SPLUNK_HOME/etc/shcluster/apps/search/lookups/&lt;/CODE&gt; directory on deployer.&lt;BR /&gt;
Step 3: I pushed the configuration changes to the cluster members through the &lt;CODE&gt;splunk apply shcluster-bundle -target &lt;A href="https://xxxx:8089" target="test_blank"&gt;https://xxxx:8089&lt;/A&gt;&lt;/CODE&gt; command&lt;/P&gt;

&lt;P&gt;I thought that would allow all members to have the same lookup table, Prior to this, all knowledge objects were created through GUI&lt;/P&gt;

&lt;P&gt;But then I found that I could not delete my own fields, alerts and other knowledge objects.&lt;/P&gt;

&lt;P&gt;As an administrator, I can't delete my own knowledge objects, but about 1% of the knowledge objects can be deleted&lt;/P&gt;

&lt;P&gt;Did i make a mistake on the cluster?So now, how do I  rescue my search header cluster and get them back to normal? &lt;/P&gt;

&lt;P&gt;may you tell me the steps?&lt;/P&gt;

&lt;P&gt;See screenshot 1:&lt;/P&gt;

&lt;P&gt;Two new directories( &lt;CODE&gt;default.old.date-bundle id&lt;/CODE&gt; ) are added to the search head ,( because I pushed twice bundles through the deployer. ).&lt;/P&gt;

&lt;P&gt;See screenshot 2:&lt;/P&gt;

&lt;P&gt;I am copying the entire search app (&lt;CODE&gt;$SPLUNK_HOME/etc/apps/search&lt;/CODE&gt;) to the deployer. And then configure the changes. Finally pushed to the cluster member&lt;/P&gt;

&lt;P&gt;Why i would use the wrong method? I always thought that only put lookup table in the  lookups directory of search app, then can call the lookup table on the Search APP(search &amp;amp;  Reporting).If the lookup table put other app directory , then  can not call the lookup table on the  Search APP (search &amp;amp; Reporting).So my idea is wrong?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3559iB1914AD790495948/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3560i2A7FF6C9ADC32DDF/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 02:46:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360508#M13301</guid>
      <dc:creator>xsstest</dc:creator>
      <dc:date>2017-09-28T02:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Search head cluster dilemma -- Is there a way to reverse this configuration issue?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360509#M13302</link>
      <description>&lt;P&gt;There appears to be some confusion here, if i have interpreted your post correctly you have pushed the lookup file from the deployer to the search heads in a cluster and now you cannot edit the lookup on the search heads?&lt;/P&gt;

&lt;P&gt;You may want to consider installing the &lt;A href="https://splunkbase.splunk.com/app/1724/"&gt;lookup file editor&lt;/A&gt; as this might make it easier for you to add lookups via the GUI.&lt;BR /&gt;
Or use the built-in &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/PivotTutorial/AddlookupfilestoSplunk"&gt;Splunk lookup functionality&lt;/A&gt; to upload your lookup and change the sharing on it so you can access it in all applications if that is what you are trying to do.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2017 14:52:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360509#M13302</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2017-09-29T14:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Search head cluster dilemma -- Is there a way to reverse this configuration issue?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360510#M13303</link>
      <description>&lt;P&gt;Thank you, I understand now. I can create an app on the deployer. then put the lookup table in the app directory&lt;CODE&gt;$SPLUNK_HOME$&lt;/CODE&gt;/splunk/etc/shcluster/apps/myapp_name/test.csv,  then push it to all the search header members. I set the lookup table to global sharing through WEBUI.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 15:40:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360510#M13303</guid>
      <dc:creator>xsstest</dc:creator>
      <dc:date>2017-10-11T15:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Search head cluster dilemma -- Is there a way to reverse this configuration issue?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360511#M13304</link>
      <description>&lt;P&gt;One more question.&lt;BR /&gt;
If one of the members uploads a lookup table via webui, will the other members copy each other?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 15:43:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360511#M13304</guid>
      <dc:creator>xsstest</dc:creator>
      <dc:date>2017-10-11T15:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Search head cluster dilemma -- Is there a way to reverse this configuration issue?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360512#M13305</link>
      <description>&lt;P&gt;Yes, lookup tables for example as per the &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/HowconfigurationworksinSHC" target="_blank"&gt;How configuration changes propagate across the search head cluster&lt;/A&gt; do replicate within the search head cluster.&lt;/P&gt;

&lt;P&gt;Also under your apps/myapp_name/ you should have a default or local directory where you put the relevant files (myapp_name/default/test.csv for example)&lt;BR /&gt;
When pushed to the search head members the files will end up in myapp_name/default/... (this way you can override the file on the search head itself)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:13:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360512#M13305</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2020-09-29T16:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Search head cluster dilemma -- Is there a way to reverse this configuration issue?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360513#M13306</link>
      <description>&lt;P&gt;Good related post for Enterprise Security running in a search cluster with the same dilema. &lt;A href="https://answers.splunk.com/answers/498425/how-do-you-update-lookups-on-a-shc-while-running-s.html"&gt;https://answers.splunk.com/answers/498425/how-do-you-update-lookups-on-a-shc-while-running-s.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 14:56:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360513#M13306</guid>
      <dc:creator>bandit</dc:creator>
      <dc:date>2018-07-18T14:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Search head cluster dilemma -- Is there a way to reverse this configuration issue?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360514#M13307</link>
      <description>&lt;P&gt;If you use the GUI or the &lt;CODE&gt;Lookup File Editor&lt;/CODE&gt; app (&lt;A href="https://splunkbase.splunk.com/app/1724/"&gt;https://splunkbase.splunk.com/app/1724/&lt;/A&gt;), these changes will be synchronized across the cluster.  Do not use the Deployer for a simple Lookup File change.  You are risking big trouble if you do.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 15:09:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Search-head-cluster-dilemma-Is-there-a-way-to-reverse-this/m-p/360514#M13307</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-18T15:09:05Z</dc:date>
    </item>
  </channel>
</rss>

