All Apps and Add-ons

Splunk_TA_Windows deployment on a Search Head

dersa
Path Finder

Hi, we have a distributed Splunk environment and I have successfully deployed the UF to Windows Server. I am getting data into my Indexer. 

My question is regarding the Search Head cluster. I believe I need to deploy the TA also to the Search Heads to get properties from the props.conf and other files.

Do I need to deploy the complete TA to my Search heads or just specific files?

Thanks in advance

Alex 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Deploy the complete TA with inputs disabled to your SH.

---
If this reply helps you, Karma would be appreciated.

nniranjanreddy
Engager

Hi, 

You can install Splunk_TA_Windows on search head by removing the inputs.conf file for managing KOs & other Search time functionalities.

Refer the below documentation:
https://docs.splunk.com/Documentation/AddOns/released/Windows/Install#Distributed_deployment_feature...


You can install this add-on on a search head cluster for all search-time functionality, but configure inputs on forwarders to avoid duplicate data collection.
Before you install this add-on to a cluster, make the following changes to the add-on package: Remove the inputs.conf file.

dersa
Path Finder

Thanks for the quick reply. I'll give it a try right now.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dersa ,

I'm agree with @richgalloway : I don't like to customize add-ons, I always prefer to use standard add-ons, eventually disabling inputs, to avoid, for the updates, to remember the customizations you did and make them every time.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...