<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk distributed environment issues in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480801#M16733</link>
    <description>&lt;P&gt;I have some questions that i hope someone can help me clarifying them :&lt;BR /&gt;
1) In an indexer cluster, can i install apps and add-ons on each indexer separatly without pushing all using the cluster master?&lt;/P&gt;

&lt;P&gt;2)If i will use cluster master, should i untar the apps and add-ons that i put in /master-apps or no need for the unpacking step ?&lt;/P&gt;

&lt;P&gt;3)how to use sendtoindexer app if i have an indexer cluster ?, I mean , what should be written in the text file exactly ?&lt;BR /&gt;
thanks in advance &lt;/P&gt;</description>
    <pubDate>Sat, 29 Feb 2020 18:40:55 GMT</pubDate>
    <dc:creator>elkhafif</dc:creator>
    <dc:date>2020-02-29T18:40:55Z</dc:date>
    <item>
      <title>splunk distributed environment issues</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480801#M16733</link>
      <description>&lt;P&gt;I have some questions that i hope someone can help me clarifying them :&lt;BR /&gt;
1) In an indexer cluster, can i install apps and add-ons on each indexer separatly without pushing all using the cluster master?&lt;/P&gt;

&lt;P&gt;2)If i will use cluster master, should i untar the apps and add-ons that i put in /master-apps or no need for the unpacking step ?&lt;/P&gt;

&lt;P&gt;3)how to use sendtoindexer app if i have an indexer cluster ?, I mean , what should be written in the text file exactly ?&lt;BR /&gt;
thanks in advance &lt;/P&gt;</description>
      <pubDate>Sat, 29 Feb 2020 18:40:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480801#M16733</guid>
      <dc:creator>elkhafif</dc:creator>
      <dc:date>2020-02-29T18:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: splunk distributed environment issues</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480802#M16734</link>
      <description>&lt;P&gt;1) Yes, but why do that?  Using the CM means not having to install apps on each indexer separately.  It also avoids the potential conflict if the same app is both locally-installed and CM-installed.&lt;/P&gt;

&lt;P&gt;2) Yes, untar the app in master-apps.&lt;/P&gt;

&lt;P&gt;3) The sendtoindexer app is installed on forwarders.  It should be placed your deployment servers's deployment-apps directory and deployed to the appropriate forwarders.   The outputs.conf file will contain the addresses for your indexers.  Alternatively, if you're using Indexer Discovery the file will contain the address of your cluster master.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Feb 2020 19:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480802#M16734</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-02-29T19:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: splunk distributed environment issues</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480803#M16735</link>
      <description>&lt;P&gt;could u please give me an example of the syntax written in the text if for example the ips of the indexers are 192.168.1.3/4 and the CM is .5 ?&lt;/P&gt;</description>
      <pubDate>Sat, 29 Feb 2020 20:03:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480803#M16735</guid>
      <dc:creator>elkhafif</dc:creator>
      <dc:date>2020-02-29T20:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: splunk distributed environment issues</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480804#M16736</link>
      <description>&lt;P&gt;1: Yes, but then use this as your ONLY method of deploying configuration changes.&lt;BR /&gt;
2: You should unpack them, but not by manually with &lt;CODE&gt;tar&lt;/CODE&gt;.  There is potentially MUCH more that happens when some complicated apps are installed (like &lt;CODE&gt;SecKit*&lt;/CODE&gt; and &lt;CODE&gt;SideView Utils&lt;/CODE&gt;) and you will BREAK the app if you just &lt;CODE&gt;untar&lt;/CODE&gt;.  Instead ALWAYS use &lt;CODE&gt;$SPLUNK_HOME/bin/splunk install&lt;/CODE&gt;&lt;BR /&gt;
3: That app should just have an &lt;CODE&gt;outputs.conf&lt;/CODE&gt; file.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Feb 2020 23:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480804#M16736</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-02-29T23:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: splunk distributed environment issues</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480805#M16737</link>
      <description>&lt;P&gt;See &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Outputsconf"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Outputsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 15:02:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/splunk-distributed-environment-issues/m-p/480805#M16737</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-03-01T15:02:16Z</dc:date>
    </item>
  </channel>
</rss>

