<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the knowledge bundle deafult behavour? [Question was asked but i was incorrect in my understanding of a knowledge bundle] in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400173#M95902</link>
    <description>&lt;P&gt;Thanks. I was incorrect in my understanding. - Thanks for the correction&lt;/P&gt;</description>
    <pubDate>Fri, 23 Nov 2018 15:29:42 GMT</pubDate>
    <dc:creator>robertlynch2020</dc:creator>
    <dc:date>2018-11-23T15:29:42Z</dc:date>
    <item>
      <title>What is the knowledge bundle deafult behavour? [Question was asked but i was incorrect in my understanding of a knowledge bundle]</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400169#M95898</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I have one search head and 2 search nodes(non clustered).&lt;/P&gt;

&lt;P&gt;I have an app installed on the search head, but i had to manually install the app to the 2 search nodes, but i get the feeling this should have happened by default with "knowledge bundle".&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/Limittheknowledgebundlesize"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/Limittheknowledgebundlesize&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Or do i have to specify my app specifically, if so how and where?&lt;BR /&gt;
When i check my "search peers" i can see "Replication Status" = Successfull&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;BR /&gt;
Robert Lynch&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 15:56:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400169#M95898</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2018-11-21T15:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: What is the knowledge bundle deafult behavour? [Question was asked but i was incorrect in my understanding of a knowledge bundle]</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400170#M95899</link>
      <description>&lt;P&gt;First, about terminology - &lt;STRONG&gt;knowledge bundle&lt;/STRONG&gt; is defined as -&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/DistSearch/Whatsearchheadssend"&gt;What search heads send to search peers&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;-- When initiating a distributed search, the search head replicates and distributes its &lt;EM&gt;knowledge objects&lt;/EM&gt; to its &lt;EM&gt;search peers&lt;/EM&gt;, or indexers. Knowledge objects include saved searches, event types, and other entities used in searching across indexes. The search head needs to distribute this material to its search peers so that they can properly execute queries on its behalf. This set of knowledge objects is called the &lt;EM&gt;knowledge bundle&lt;/EM&gt;. &lt;/P&gt;

&lt;P&gt;And &lt;STRONG&gt;Replication Status&lt;/STRONG&gt; is about data replication across indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 16:37:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400170#M95899</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-11-21T16:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: What is the knowledge bundle deafult behavour? [Question was asked but i was incorrect in my understanding of a knowledge bundle]</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400171#M95900</link>
      <description>&lt;P&gt;If your indexers are currently not clustered, you could use a Deployment Server to push the app to all of your indexers.  In a clustered environment, you would use the Cluster Master to do this.&lt;/P&gt;

&lt;P&gt;Do you currently have a Deployment Server?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 16:46:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400171#M95900</guid>
      <dc:creator>kmorris_splunk</dc:creator>
      <dc:date>2018-11-21T16:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: What is the knowledge bundle deafult behavour? [Question was asked but i was incorrect in my understanding of a knowledge bundle]</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400172#M95901</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Thanks for the replay.&lt;BR /&gt;
I don't have a Deployment server nor cluster master - what one would be easier to apply, i am assuming i need to get one.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/Updating/Planadeployment"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/Updating/Planadeployment&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;However i am reading that a deployment server cant be a search head also. My plan was to change things in my search-head and these changes get pushed out to  my search nodes.&lt;/P&gt;

&lt;P&gt;So for example if i am logging into my search head and I make a change to my APP [Datamodel limits.conf etc..], I want this change to be take effect in my search nodes.&lt;/P&gt;

&lt;P&gt;So if this is not possible how does it work? So would a cluster master be easier for this?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Rob&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 15:08:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400172#M95901</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2018-11-22T15:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: What is the knowledge bundle deafult behavour? [Question was asked but i was incorrect in my understanding of a knowledge bundle]</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400173#M95902</link>
      <description>&lt;P&gt;Thanks. I was incorrect in my understanding. - Thanks for the correction&lt;/P&gt;</description>
      <pubDate>Fri, 23 Nov 2018 15:29:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400173#M95902</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2018-11-23T15:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: What is the knowledge bundle deafult behavour? [Question was asked but i was incorrect in my understanding of a knowledge bundle]</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400174#M95903</link>
      <description>&lt;P&gt;HI&lt;/P&gt;

&lt;P&gt;I started to us a Forwarder Management on a deployment server and it worked thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;

&lt;P&gt;Robbie &lt;/P&gt;</description>
      <pubDate>Sat, 24 Nov 2018 10:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-knowledge-bundle-deafult-behavour-Question-was-asked/m-p/400174#M95903</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2018-11-24T10:56:33Z</dc:date>
    </item>
  </channel>
</rss>

