All Apps and Add-ons

Does the Alert Manager app work in a search head cluster?

kiran331
Builder

Hi

Does Alert Manager support clustering? I installed the TA on indexers and search heads, and the app on 2 Search Heads. The app is working individually on both SH's, but is there a way to see all alerts on one Search Head?

0 Karma
1 Solution

Masa
Splunk Employee
Splunk Employee

I believe this question should go to the author of the app to confirm if they support Search Head Clustering. I could not find comments regarding Search Head Clustering in the app's doc page http://docs.alertmanager.info/Documentation

View solution in original post

0 Karma

Simon
Contributor

As long as you're forwarding events from Search Heads to your indexing layer, you're good to go with SHC. We're using standard technologies (KV Store, Indexing, Lookups, Knowledge Objects as well as REST extensions) which are all supported by SHC.
Although we know several customers are using the Alert Manager on Search Head Clusters, we lack of feedback about issues.
Please let us known if you have any problems.

0 Karma

kiran331
Builder

Thank you!

0 Karma

Masa
Splunk Employee
Splunk Employee

I believe this question should go to the author of the app to confirm if they support Search Head Clustering. I could not find comments regarding Search Head Clustering in the app's doc page http://docs.alertmanager.info/Documentation

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...