<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Single deployment app for Prod, Test &amp; DR. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367401#M169867</link>
    <description>&lt;P&gt;Don't name your indexes differently. It's a terrible idea. When you create dashboards, reports, extractions, etc in lower envs, porting to higher envs could be problematic. Use tags or lookups to differentiate your environments if you really need to. Speaking from experience.&lt;/P&gt;</description>
    <pubDate>Tue, 01 May 2018 15:09:40 GMT</pubDate>
    <dc:creator>twinspop</dc:creator>
    <dc:date>2018-05-01T15:09:40Z</dc:date>
    <item>
      <title>Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367399#M169865</link>
      <description>&lt;P&gt;How we usually do business is; on our deployment server, we will create an app specific to its environment. Which can get repetitive and creates some overhead? Is it possible to consolidate this? &lt;/P&gt;

&lt;P&gt;So, for instance, consider the following example:&lt;/P&gt;

&lt;P&gt;We use Atlassian suite with a total of 7 products(Bamboo, Jira, etc.), each with Prod, Test, and DR environments. Is it possible to create a single app., for each product with the ability to differentiate between indices? i.e. - jira_test, jira_prod &amp;amp; jira-dr.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:17:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367399#M169865</guid>
      <dc:creator>Harinder_Singh</dc:creator>
      <dc:date>2020-09-29T19:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367400#M169866</link>
      <description>&lt;P&gt;Am I getting this right?&lt;BR /&gt;
You don't want to have three copies of your app, with the only difference being which index they should put their index into? &lt;/P&gt;</description>
      <pubDate>Sun, 29 Apr 2018 08:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367400#M169866</guid>
      <dc:creator>bjoernhansen</dc:creator>
      <dc:date>2018-04-29T08:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367401#M169867</link>
      <description>&lt;P&gt;Don't name your indexes differently. It's a terrible idea. When you create dashboards, reports, extractions, etc in lower envs, porting to higher envs could be problematic. Use tags or lookups to differentiate your environments if you really need to. Speaking from experience.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 15:09:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367401#M169867</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2018-05-01T15:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367402#M169868</link>
      <description>&lt;P&gt;That is correct. I would really prefer to not have to create 21 apps for all Atlassian applications. From what I have read so far, this would require putting together a bash script placed on the deployment server. So each time the app servers call home, it knows what index to populate. &lt;/P&gt;

&lt;P&gt;Thoughts? Am I least going in the right direction? &lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 21:44:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367402#M169868</guid>
      <dc:creator>Harinder_Singh</dc:creator>
      <dc:date>2018-05-01T21:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367403#M169869</link>
      <description>&lt;P&gt;Are you saying have one index per application, e.g. - Bamboo, and distinguish between environments based on source type?  &lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 21:51:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367403#M169869</guid>
      <dc:creator>Harinder_Singh</dc:creator>
      <dc:date>2018-05-01T21:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367404#M169870</link>
      <description>&lt;P&gt;I don't think so I heard about such script. Do you have the reference link where you've seen it?&lt;/P&gt;

&lt;P&gt;So, data for all environments of your Atlassian apps go to same Splunk instance (and that's the reason you've three different indexes)?&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 21:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367404#M169870</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-05-01T21:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367405#M169871</link>
      <description>&lt;P&gt;I don't think there's a specific link, it was just me putting 2 and 2 together.&lt;BR /&gt;
Yes, data goes to a 2 node cluster indexers. &lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 22:23:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367405#M169871</guid>
      <dc:creator>Harinder_Singh</dc:creator>
      <dc:date>2018-05-01T22:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367406#M169872</link>
      <description>&lt;P&gt;Distinguish by host would be most common. You should keep sourcetype definitions consistent across environments. Again, in my experience.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 01:39:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367406#M169872</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2018-05-02T01:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367407#M169873</link>
      <description>&lt;P&gt;I would go with using the same index for your all Atlassian suite apps and env.&lt;BR /&gt;
However I'd prefer to make use of event types and Tags to differentiate between my environments and apps.&lt;/P&gt;

&lt;P&gt;E.g. If Hosts or Source IPs can be used to differentiate the environmental data, you could write an event type to say - &lt;BR /&gt;
Host = xxx OR Host = yyy OR Host = zzz ...&lt;BR /&gt;
Also create a Tag for this event type.&lt;/P&gt;

&lt;P&gt;Also whatever the differentiator you have for recognizing the app specific event e.g. an App field, create an event type as&lt;BR /&gt;
App = Jira&lt;BR /&gt;
Also create a Tag for this event type.&lt;/P&gt;

&lt;P&gt;Finally you would be able to see your data by simply querying something as :&lt;BR /&gt;
Index = Atlassian tag = Production tag = Jira&lt;/P&gt;

&lt;P&gt;Let me know if that suits you or anymore details are required.&lt;BR /&gt;
Thanks.&lt;BR /&gt;
Please upvote or accept as answer if it serves your purpose &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 08:48:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367407#M169873</guid>
      <dc:creator>amitm05</dc:creator>
      <dc:date>2018-05-02T08:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367408#M169874</link>
      <description>&lt;P&gt;And also to mention that this would give you more flexibility on your searches. If in case you want to search over all bamboo data irrespective of your environment, you could simply say:&lt;BR /&gt;
Index = Atlassian tag = Bamboo&lt;/P&gt;

&lt;P&gt;And Yes of course, for once this will require you to do little work to setup all those tags and event types.&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 08:51:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367408#M169874</guid>
      <dc:creator>amitm05</dc:creator>
      <dc:date>2018-05-02T08:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367409#M169875</link>
      <description>&lt;P&gt;@amitm05 this makes perfect sense and fits our use case. I will start working on implementing and get back to you with questions/updates I have. &lt;/P&gt;

&lt;P&gt;Thanks a lot! &lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 03:59:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367409#M169875</guid>
      <dc:creator>Harinder_Singh</dc:creator>
      <dc:date>2018-05-04T03:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: Single deployment app for Prod, Test &amp; DR.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367410#M169876</link>
      <description>&lt;P&gt;Sure. Do let me know if it works out for you. Cheers !&lt;/P&gt;</description>
      <pubDate>Fri, 04 May 2018 11:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Single-deployment-app-for-Prod-Test-DR/m-p/367410#M169876</guid>
      <dc:creator>amitm05</dc:creator>
      <dc:date>2018-05-04T11:50:46Z</dc:date>
    </item>
  </channel>
</rss>

