All Apps and Add-ons

Installing a TA in a Splunk Cluster

agodoy
Communicator

I have the SoS TA and *nix TA installed on my search peers. I have also enabled the inputs and deployed the bundle via cluster master (5.0.4 permission issue is now gone). However, I do not see any data from my search peers.

Do I also need to configure outputs.conf so that the search peers send that to the themselves?

Am I missing something else?

Thanks

0 Karma
1 Solution

agodoy
Communicator

I found the problem. Documentation.

I was putting the TA directories in $SPLUNK_HOME/etc/master-apps/_cluster, but they need to be in $SPLUNK_HOME/etc/master-apps .

View solution in original post

agodoy
Communicator

I found the problem. Documentation.

I was putting the TA directories in $SPLUNK_HOME/etc/master-apps/_cluster, but they need to be in $SPLUNK_HOME/etc/master-apps .

agodoy
Communicator

Nothing from ExecProcessor at all.

0 Karma

sowings
Splunk Employee
Splunk Employee

Do you see log events from ExecProcessor indicating a permissions failure, or perhaps some other error condition?

It sounds like the steps you've taken are correct.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...