All Apps and Add-ons

In a distributed search environment, can we blacklist apps in distsearch.conf and prevent it from being part of the bundle replication to search peers?

ben_leung
Builder

In a distributed search environment, can we blacklist the app in distsearch.conf and prevent it from being part of the bundle replication to search peers?

I have a search head cluster with the Machine Learning Toolkit and Python for Scientific Computing (for Linux 64-bit). I added the following to the blacklist stanza under distsearch.conf in the search heads - Will things still function if app is not replicated to search peers?

[replicationBlacklist]
ml_tool_kit = apps/Splunk_ML_Toolkit/...
scientific_python = apps/Splunk_SA_Scientific_Python_linux_x86_64/...
0 Karma

ben_leung
Builder

Does not look like you can. If you go into the app's search view, run a query e.g. index=_internal | head 1

Errors from indexers as shown:

12-07-2016 23:42:45.412 +0000 ERROR StreamedSearch - sid=remote_sh-abc-2.my.domain.com_1481154165.41768_6510209A-0131-4200-8B9D-63C774CA33FF, Search process did not exit cleanly, exit_code=255, description="exited with code 255". Please look in search.log for this peer in the Job Inspector for more info.
0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...