All Apps and Add-ons

Typo in Splunk for VMware Install Doc deployment.apps

tzhmaba2
Path Finder

Hi,

The Install Guide for VMware App 3.1.0 says:

http://docs.splunk.com/Documentation/VMW/3.1/Install/Installonyoursearchheadorindexer

Note that on a dedicated indexer, for a valid install, the following files exist in $SPLUNK_HOME/etc/deployment-apps:

    /SA-Utils/… 
    /SA-Hydra/… 
    /Splunk_TA_vcenter/… 
    /Splunk_TA_vmware/… 
    /Splunk_TA_esxilogs/...

Do you really mean etc/deployment-apps/?? Are these apps being somehow deployed? Where to? Otherwise what's the point of having them in etc/deployment-apps/?

Just to make sure: The above mentioned apps are to be moved away from etc/apps/ into /etc/deployment-apps/ on a dedicated indexer, right? Not additionally copied?

Regards,
Bartosz

Tags (1)
0 Karma
1 Solution

rgantly_splunk
Splunk Employee
Splunk Employee

In single-machine Splunk deployments, where the indexing and search capability resides on the one host, on the host that is your indexer and search head, install the splunk_app_vmware--.zip. It contains all of the components you need. When you unzip the file in $SPLUNK_HOME, it automatically puts the files in the correct location $SPLUNK_HOME/etc/apps.

In a distributed search environment, where indexing and search functions are split, you ONLY need the SA's and TA's installed on the indexer. The /etc/deployment-apps folder is provided to give you the files you need.
The process is as follows:
1. Install the splunk_app_vmware--.zip on the search head.
2. On each search peer (indexer) install all of the SA's and TA's.

The component matrix shows where the bits go. See: http://docs.splunk.com/Documentation/VMW/latest/Install/Componentreferencetable#Component_Distributi...

I hope this helps.

View solution in original post

rgantly_splunk
Splunk Employee
Splunk Employee

In single-machine Splunk deployments, where the indexing and search capability resides on the one host, on the host that is your indexer and search head, install the splunk_app_vmware--.zip. It contains all of the components you need. When you unzip the file in $SPLUNK_HOME, it automatically puts the files in the correct location $SPLUNK_HOME/etc/apps.

In a distributed search environment, where indexing and search functions are split, you ONLY need the SA's and TA's installed on the indexer. The /etc/deployment-apps folder is provided to give you the files you need.
The process is as follows:
1. Install the splunk_app_vmware--.zip on the search head.
2. On each search peer (indexer) install all of the SA's and TA's.

The component matrix shows where the bits go. See: http://docs.splunk.com/Documentation/VMW/latest/Install/Componentreferencetable#Component_Distributi...

I hope this helps.

tzhmaba2
Path Finder

All right. Thanks for the explanation. The sentence about the components being in etc/deployment-apps could be a little bit more descriptive.

However it's clear now.

Regards, Bartosz

0 Karma

kheli
Path Finder

it means on dedicated indexers, those apps must be installed. If you have deployment server, please ensure those apps are copied to the deployment-apps folder of the deployment server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...