All Apps and Add-ons

Knowledge bundles and deployed apps

rtadams89
Contributor

If I have an app that contains lookup tables installed on my search heads AND on my indexers, can I blacklist that app from being replicated in the knowledge bundle (to reduce the bundle size)? It would seem that if the same lookup apps exist on both the search head and indexer, there would be no need to replicate the same data again from from search head to indexer...

Tags (1)
0 Karma

kaufmanm
Communicator

I don't know that this will work if you need to use the lookup on the search nodes, but I think it's your best bet, so I'd try it out and see what happens. On the search head, edit distsearch.conf and add the below stanza:

[replicationBlacklist]
large_lookup = name_of_lookup_file.csv

Then restart Splunk on the search head and see if the searches you need still work.

Source: Splunk docs

0 Karma

rtadams89
Contributor

I'm trying this now, but due to the number of apps and the variety of things I would like to blacklist (e.g., in addition to the lookup files, there are a bunch of bat/py/sh scripts, props/transforms .conf files, etc.) I'm not sure I can test all potential issues.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...