All Apps and Add-ons

Splunk Cloud app/add-ons installs & search heads

TimmL
Engager

Hello!

We are new to Splunk Cloud and have a question about installing app/add-ons that we couldn't find definitive information on in the documentation.

We have 3 instances, IDM, Search head 1, and Search head 2 which is our Enterprise Security (ES) instance.

Which one is the indexer? The IDM instance is a sort of Heavy forwarder correct?

When installing apps such as the 'Splunk Add-on for F5 BIG-IP' or the 'Cloudflare App for Splunk' the instructions say to install on the search head(s), Should they be installed on Both search heads? Or just one? What are the advantages or disadvantages of either?

Sorry for the barrage of questions but we are having trouble wrapping our head around how these instances all work together and how the apps interact.
Thanks!

Labels (2)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Your Splunk Cloud indexers are there, but are mostly hidden.  Of the three instances listed, none is an indexer since one of them is an IDM (similar to an HF) and the others are search heads.

When installing apps, just install them on the SH where they will be used.  Splunk Cloud will know which pieces of the app need to be on the indexers and will install them there as well.

Since ES can be a resource hog, only install an app on that search head if it needs to be used with ES.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Your Splunk Cloud indexers are there, but are mostly hidden.  Of the three instances listed, none is an indexer since one of them is an IDM (similar to an HF) and the others are search heads.

When installing apps, just install them on the SH where they will be used.  Splunk Cloud will know which pieces of the app need to be on the indexers and will install them there as well.

Since ES can be a resource hog, only install an app on that search head if it needs to be used with ES.

---
If this reply helps you, Karma would be appreciated.

TimmL
Engager

Great thank you thats exactly what we were looking for!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...