All Apps and Add-ons

Splunk_TA_Windows deployment on a Search Head

dersa
Path Finder

Hi, we have a distributed Splunk environment and I have successfully deployed the UF to Windows Server. I am getting data into my Indexer. 

My question is regarding the Search Head cluster. I believe I need to deploy the TA also to the Search Heads to get properties from the props.conf and other files.

Do I need to deploy the complete TA to my Search heads or just specific files?

Thanks in advance

Alex 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Deploy the complete TA with inputs disabled to your SH.

---
If this reply helps you, Karma would be appreciated.

nniranjanreddy
Engager

Hi, 

You can install Splunk_TA_Windows on search head by removing the inputs.conf file for managing KOs & other Search time functionalities.

Refer the below documentation:
https://docs.splunk.com/Documentation/AddOns/released/Windows/Install#Distributed_deployment_feature...


You can install this add-on on a search head cluster for all search-time functionality, but configure inputs on forwarders to avoid duplicate data collection.
Before you install this add-on to a cluster, make the following changes to the add-on package: Remove the inputs.conf file.

dersa
Path Finder

Thanks for the quick reply. I'll give it a try right now.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dersa ,

I'm agree with @richgalloway : I don't like to customize add-ons, I always prefer to use standard add-ons, eventually disabling inputs, to avoid, for the updates, to remember the customizations you did and make them every time.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...