All Apps and Add-ons

Update apps in Search Heads from deployer

Jhojan
New Member

Hello,

Last week I've been trying to implement a JS script in a distributed environment, and while it worked fine in a single machine, the replication has not been made in all of the SH.

The question is: How can I deploy the changes made alongside the SH ? , already tried to use the command: splunk reload deploy-server


and while it didn't return any error message, the changes were not made. As a workaround I've tried to apply the changes in a SH then wait for it to replicate in the others, which seemingly worked fine. Still, isn't there a way (like the command listed before) to force changes among the SH ?

Thanks in advance.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you individual SH's which you are managing by Deployment Server or have you a SH Cluster with Deployer?

0 Karma

manjunathmeti
Champion

You need to push updated apps from the deployer server to all the search heads in the cluster.

If you make a change on one of the search head and it is replicated to other search heads then you don't need to push the apps but if not replicated then you need to copy changes (app directory) from that search head server($SPLUNK_HOME/etc/shcluster/apps/<app>/)) to the deployer server (in $SPLUNK_HOME/etc/apps/<app>/) and push to all search heads.

Check this: https://docs.splunk.com/Documentation/Splunk/8.1.2/DistSearch/PropagateSHCconfigurationchanges

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Jhojan,

the command "splunk reload deploy-server" isn't for Deployer but ony for Deployment Server.

if you have to deploy a configuration from Deployr to Search Heads in Cluster you have to use the command

splunk apply shcluster-bundle -target <URI>:<management_port> -auth <username>:<password>

described at https://docs.splunk.com/Documentation/Splunk/8.1.2/DistSearch/PropagateSHCconfigurationchanges#Push_...

or, preserving lookups:

splunk apply shcluster-bundle -target <URI>:<management_port> -preserve-lookups true -auth <username>:<password>

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...