All Apps and Add-ons

SoS app cluster master view

herterich
Explorer

Hi all,

we are running a splunk cluster (Version 5.0.2) with pooled searchheads. We installed the SoS app on our searchheads which will work fine. Only the "Cluster Master View" will not provide any information. Looking in the dashboards xml the reason might be, that the searches will do a rest connection to the localhost (which is the searchhead and does not provide this information). Changing the rest search from splunk_server=localhost to splunk_server= will not work, because the masternode is not defined as a search peer for the searchhead.

Any ideas how to change this. Or should we install sos app on master node which is as far as I know not srecommended.

Regards
Christian

1 Solution

hexx
Splunk Employee
Splunk Employee

The Cluster Master view is indeed designed to only work when consulted from the master instance. There should be no issues installing S.o.S on the cluster master, it is for the most an "inert" app and the couple of scheduled searches it runs to maintain its assets are lightweight.

View solution in original post

hexx
Splunk Employee
Splunk Employee

The Cluster Master view is indeed designed to only work when consulted from the master instance. There should be no issues installing S.o.S on the cluster master, it is for the most an "inert" app and the couple of scheduled searches it runs to maintain its assets are lightweight.

hexx
Splunk Employee
Splunk Employee

Given that we are using the "rest" search command, the master would need to be a search peer of the search-head for that to work. It's possible, but not recommended and would require to modify the view.

0 Karma

herterich
Explorer

thx, means there is no way to do a rest request from the searchhead to the master node?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...