All Apps and Add-ons

Where do I deploy the ta-forwarderquery app

msudhindra
Path Finder

Hi,

The app looks very interesting.
We have a central deployment server that pushes out all the apps, to all Splunk compoenents.

Can you please give me some guidance on where I push this app out to - Indexers, forwarders or Search heads or all 3 ?

Thanks,
Madan Sudhindra

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

The description on the app's page says this:

Usually you would install it on the deployment server and have a firewall rule to open port 8089 on all forwarders etc from this server.

https://splunkbase.splunk.com/app/2775/

From your list of three choices the app would be most appropriate on a search head and useless on an indexer or forwarder.

View solution in original post

0 Karma

dominiquevocat
Motivator

I have it on the deploy server. Any searchhead will do provided you have firewall rules that allow you to connect to the rest port of the forwarder (8089 by default but you can change it in the .conf).

Hope this helps.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

The description on the app's page says this:

Usually you would install it on the deployment server and have a firewall rule to open port 8089 on all forwarders etc from this server.

https://splunkbase.splunk.com/app/2775/

From your list of three choices the app would be most appropriate on a search head and useless on an indexer or forwarder.

0 Karma

msudhindra
Path Finder

Thank you @martin_mueller and @dominiquevocat

I will give this a try and let you know how it works out

Thanks,
Madan

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...