<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to deploy the Splunk App for Enterprise Security in an Indexer and Search Head Clustering environment? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163570#M682</link>
    <description>&lt;P&gt;If you have SHC configured, you need 3 search heads, you can follow the Documentation for deploying ES in SHC. It will involve all &lt;CODE&gt;SA-*&lt;/CODE&gt; &lt;CODE&gt;SplunkforEnterpriseSecurity*&lt;/CODE&gt; &lt;CODE&gt;DA-*&lt;/CODE&gt; folders.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Apr 2015 09:48:14 GMT</pubDate>
    <dc:creator>esix_splunk</dc:creator>
    <dc:date>2015-04-23T09:48:14Z</dc:date>
    <item>
      <title>How to deploy the Splunk App for Enterprise Security in an Indexer and Search Head Clustering environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163567#M679</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I am trying to simulate a cluster environment for the Splunk App for Enterprise Security. The setup is:&lt;/P&gt;

&lt;P&gt;-Two Indexers in a cluster with Rep Factor =2 , search factor=2&lt;BR /&gt;
-One search head for ES APP other one for third party apps.&lt;BR /&gt;
-Dedicated Cluster Master &amp;amp; Deployer on a single machine.&lt;/P&gt;

&lt;P&gt;I have installed the ES APP in the on the deployer and copied &lt;CODE&gt;SA-ForIndexers, TA-*, Splunk_TA*, Splunk_SA*&lt;/CODE&gt; files to master-apps and pushed to the Indexer cluster. With this, it is able to create the indexes.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Would like to know what are all the directories i need to copy/Push to the ES APP search head node?&lt;/LI&gt;
&lt;LI&gt;Do i need to create search head cluster, or just i can copy directly ES app related files for the search head?&lt;/LI&gt;
&lt;LI&gt;How do I ensure that the search head sends all the data to the Indexer cluster?&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Thanks &lt;BR /&gt;
siddiqu.T&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 09:21:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163567#M679</guid>
      <dc:creator>masiddiqu</dc:creator>
      <dc:date>2015-04-23T09:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to deploy the Splunk App for Enterprise Security in an Indexer and Search Head Clustering environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163568#M680</link>
      <description>&lt;P&gt;Indexer Clustering and Search Head Clustering are two separate and distinct features. You need to understand the basics of both in order to run ES in both. Based on your environment description, you do not have Search Head Clustering in mind.&lt;/P&gt;

&lt;P&gt;Regarding Indexer Clustering, you need a working cluster before you install ES. Once you have a valid working clustered indexer environment, then you can install ES. There is a SA-ForIndexers that comes with ES, this would be placed on your Cluster Master and distributed to each indexer. This is not through the deployer, the deployer is used for SHC.&lt;/P&gt;

&lt;P&gt;For SHC, again you need to understand how this works before you try and deploy ES on this. There is a large list of issues you need to be aware of and understand before you even attempt this. Make sure you read the documentation at : &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/ES/3.2.2/Install/AdvancedImp"&gt;http://docs.splunk.com/Documentation/ES/3.2.2/Install/AdvancedImp&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 09:28:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163568#M680</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2015-04-23T09:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to deploy the Splunk App for Enterprise Security in an Indexer and Search Head Clustering environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163569#M681</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have completed the Index cluster and pushed the SA-ForIndexesrs via cluster master to the indexers. The indexes are created on both indexers.&lt;/P&gt;

&lt;P&gt;For the search Head cluster, would like to know what are all directories/files  we need to push to  the search head  nodes via deployer.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
siddiqu.T&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 09:40:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163569#M681</guid>
      <dc:creator>masiddiqu</dc:creator>
      <dc:date>2015-04-23T09:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to deploy the Splunk App for Enterprise Security in an Indexer and Search Head Clustering environment?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163570#M682</link>
      <description>&lt;P&gt;If you have SHC configured, you need 3 search heads, you can follow the Documentation for deploying ES in SHC. It will involve all &lt;CODE&gt;SA-*&lt;/CODE&gt; &lt;CODE&gt;SplunkforEnterpriseSecurity*&lt;/CODE&gt; &lt;CODE&gt;DA-*&lt;/CODE&gt; folders.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2015 09:48:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-deploy-the-Splunk-App-for-Enterprise-Security-in-an/m-p/163570#M682</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2015-04-23T09:48:14Z</dc:date>
    </item>
  </channel>
</rss>

