All Apps and Add-ons

Typo in Splunk for VMware Install Doc deployment.apps

tzhmaba2
Path Finder

Hi,

The Install Guide for VMware App 3.1.0 says:

http://docs.splunk.com/Documentation/VMW/3.1/Install/Installonyoursearchheadorindexer

Note that on a dedicated indexer, for a valid install, the following files exist in $SPLUNK_HOME/etc/deployment-apps:

    /SA-Utils/… 
    /SA-Hydra/… 
    /Splunk_TA_vcenter/… 
    /Splunk_TA_vmware/… 
    /Splunk_TA_esxilogs/...

Do you really mean etc/deployment-apps/?? Are these apps being somehow deployed? Where to? Otherwise what's the point of having them in etc/deployment-apps/?

Just to make sure: The above mentioned apps are to be moved away from etc/apps/ into /etc/deployment-apps/ on a dedicated indexer, right? Not additionally copied?

Regards,
Bartosz

Tags (1)
0 Karma
1 Solution

rgantly_splunk
Splunk Employee
Splunk Employee

In single-machine Splunk deployments, where the indexing and search capability resides on the one host, on the host that is your indexer and search head, install the splunk_app_vmware--.zip. It contains all of the components you need. When you unzip the file in $SPLUNK_HOME, it automatically puts the files in the correct location $SPLUNK_HOME/etc/apps.

In a distributed search environment, where indexing and search functions are split, you ONLY need the SA's and TA's installed on the indexer. The /etc/deployment-apps folder is provided to give you the files you need.
The process is as follows:
1. Install the splunk_app_vmware--.zip on the search head.
2. On each search peer (indexer) install all of the SA's and TA's.

The component matrix shows where the bits go. See: http://docs.splunk.com/Documentation/VMW/latest/Install/Componentreferencetable#Component_Distributi...

I hope this helps.

View solution in original post

rgantly_splunk
Splunk Employee
Splunk Employee

In single-machine Splunk deployments, where the indexing and search capability resides on the one host, on the host that is your indexer and search head, install the splunk_app_vmware--.zip. It contains all of the components you need. When you unzip the file in $SPLUNK_HOME, it automatically puts the files in the correct location $SPLUNK_HOME/etc/apps.

In a distributed search environment, where indexing and search functions are split, you ONLY need the SA's and TA's installed on the indexer. The /etc/deployment-apps folder is provided to give you the files you need.
The process is as follows:
1. Install the splunk_app_vmware--.zip on the search head.
2. On each search peer (indexer) install all of the SA's and TA's.

The component matrix shows where the bits go. See: http://docs.splunk.com/Documentation/VMW/latest/Install/Componentreferencetable#Component_Distributi...

I hope this helps.

tzhmaba2
Path Finder

All right. Thanks for the explanation. The sentence about the components being in etc/deployment-apps could be a little bit more descriptive.

However it's clear now.

Regards, Bartosz

0 Karma

kheli
Path Finder

it means on dedicated indexers, those apps must be installed. If you have deployment server, please ensure those apps are copied to the deployment-apps folder of the deployment server.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...