All Apps and Add-ons

Splunk_TA_Windows deployment on a Search Head

dersa
Path Finder

Hi, we have a distributed Splunk environment and I have successfully deployed the UF to Windows Server. I am getting data into my Indexer. 

My question is regarding the Search Head cluster. I believe I need to deploy the TA also to the Search Heads to get properties from the props.conf and other files.

Do I need to deploy the complete TA to my Search heads or just specific files?

Thanks in advance

Alex 

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Deploy the complete TA with inputs disabled to your SH.

---
If this reply helps you, Karma would be appreciated.

nniranjanreddy
Engager

Hi, 

You can install Splunk_TA_Windows on search head by removing the inputs.conf file for managing KOs & other Search time functionalities.

Refer the below documentation:
https://docs.splunk.com/Documentation/AddOns/released/Windows/Install#Distributed_deployment_feature...


You can install this add-on on a search head cluster for all search-time functionality, but configure inputs on forwarders to avoid duplicate data collection.
Before you install this add-on to a cluster, make the following changes to the add-on package: Remove the inputs.conf file.

dersa
Path Finder

Thanks for the quick reply. I'll give it a try right now.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dersa ,

I'm agree with @richgalloway : I don't like to customize add-ons, I always prefer to use standard add-ons, eventually disabling inputs, to avoid, for the updates, to remember the customizations you did and make them every time.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Cloud Platform | Customer Change Announcement: Email Notification Will Be Available ...

The Notification Team is migrating our email service provider since currently there’s no support ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...