<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Enterprise Security on SHC in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745444#M12504</link>
    <description>&lt;P&gt;I have installed ES on deployer as suggested by splunk docs, then transfered this app to /opt/splunk/etc/shcluster/apps and pushed the apps to my cluster.&lt;/P&gt;&lt;P&gt;but still when I open ES on any search head it still says Post instal configurations and when I click configure it says you can not do it on SHC member&lt;/P&gt;</description>
    <pubDate>Sun, 04 May 2025 08:50:32 GMT</pubDate>
    <dc:creator>Nawab</dc:creator>
    <dc:date>2025-05-04T08:50:32Z</dc:date>
    <item>
      <title>Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745444#M12504</link>
      <description>&lt;P&gt;I have installed ES on deployer as suggested by splunk docs, then transfered this app to /opt/splunk/etc/shcluster/apps and pushed the apps to my cluster.&lt;/P&gt;&lt;P&gt;but still when I open ES on any search head it still says Post instal configurations and when I click configure it says you can not do it on SHC member&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 08:50:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745444#M12504</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2025-05-04T08:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745445#M12505</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244855"&gt;@Nawab&lt;/a&gt;&amp;nbsp; -&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Please make sure that you followed all pre-requisites for SHC and ES on SHC.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/8.0.2/Install/InstallSplunkESinSHC" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/ES/8.0.2/Install/InstallSplunkESinSHC&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 08:58:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745445#M12505</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-04T08:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745446#M12506</link>
      <description>&lt;P&gt;Followed every thing exactly described in docs&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 09:00:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745446#M12506</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2025-05-04T09:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745447#M12507</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244855"&gt;@Nawab&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Installing ES on a Search Head Cluster&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Deployer:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1. On the Splunk toolbar, select Apps &amp;gt; Manage Apps and click&amp;nbsp;Install app from file&lt;BR /&gt;2. Click Choose File and select the Splunk Enterprise Security file&lt;BR /&gt;3. Click Upload to begin the installation&lt;BR /&gt;4. Click Continue to app setup page&lt;BR /&gt;5. Click Start Configuration Process, and wait for it to complete&lt;BR /&gt;6. Use the Deployer to deploy ES to the cluster members. From the Deployer run:&lt;/P&gt;&lt;P&gt;/opt/splunk/bin/splunk apply shcluster-bundle&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 09:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745447#M12507</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-04T09:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745448#M12508</link>
      <description>&lt;P&gt;I followed these steps, installed ES on deployer, configured it. Mission control is not working on deployer, then I copied ES to shcluster/apps and pushed the configuration. now all DA-ESS and SA apps are present in apps of each SHC member, but still when I click ES app or mission control app on cluster member it says continue to setup page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure why&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 09:38:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745448#M12508</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2025-05-04T09:38:45Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745449#M12509</link>
      <description>&lt;P&gt;Wait. As far as I remember (it's been some time since I did it last time) you don't manually copy anything. When you run the installer in deployer mode it takes care of preparing the shcluster bundle. That's why you run it exactly as described - upload the app to the deployer, run the installer on the deployer, apply shcluster-bundle. No manual copying stuff anywhere.&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 09:50:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745449#M12509</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-05-04T09:50:04Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745450#M12510</link>
      <description>&lt;P&gt;I tried it again, usign the same method you suggested,&lt;BR /&gt;&lt;BR /&gt;deployed and configured the app on deployer and pushed the config bundle, but its still the same&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 10:26:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745450#M12510</guid>
      <dc:creator>Nawab</dc:creator>
      <dc:date>2025-05-04T10:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745453#M12511</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/244855"&gt;@Nawab&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Reconfiguring&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Splunk&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Enterprise&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Security&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;is&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;what&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;I&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;would&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;advise&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;you&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;to&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;do,&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;however&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;if&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;problem&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;persists,&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;open&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;support&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ticket.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/8.0.40/Install/InstallSplunkESinSHC#Installing_Splunk_Enterprise_Security_in_a_search_head_cluster_environment" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/ES/8.0.40/Install/InstallSplunkESinSHC#Installing_Splunk_Enterprise_Security_in_a_search_head_cluster_environment&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 04 May 2025 12:42:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745453#M12511</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-04T12:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security on SHC</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745819#M12512</link>
      <description>&lt;P&gt;Yes, this is right. There's no copy/pasting. We may need to update some parameters to support larger upload, but apart from that we can simply upload the ES package from the UI, perform the setup and deploy the Bundle.&lt;/P&gt;</description>
      <pubDate>Fri, 09 May 2025 01:45:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-on-SHC/m-p/745819#M12512</guid>
      <dc:creator>meetmshah</dc:creator>
      <dc:date>2025-05-09T01:45:01Z</dc:date>
    </item>
  </channel>
</rss>

