All Apps and Add-ons

how to install an app on a search head cluster?

xsstest
Communicator

hello~ everyone

I have a search head cluster,It has the following members: two search heads, a search captain, and a deployer. How do I install APP in a search cluster? Is the way to distribute bundles to install APP?
Is there a relevant documentation guide?

Tags (1)
0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

So first, 2 members doesnt meet the minimum requirements for a SHC. If you are using this in a lab environment, its ok, but in production this is not recommended.

Now, documentation. Have you seen docs.splunk.com? Start there.

More directly :
https://docs.splunk.com/Documentation/Splunk/6.6.1/DistSearch/AboutSHC
https://docs.splunk.com/Documentation/Splunk/6.6.1/DistSearch/SHCarchitecture

For deploying apps, you have to push from the Deployer -
http://docs.splunk.com/Documentation/Splunk/6.6.1/DistSearch/PropagateSHCconfigurationchanges

Happy reading!

View solution in original post

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

So first, 2 members doesnt meet the minimum requirements for a SHC. If you are using this in a lab environment, its ok, but in production this is not recommended.

Now, documentation. Have you seen docs.splunk.com? Start there.

More directly :
https://docs.splunk.com/Documentation/Splunk/6.6.1/DistSearch/AboutSHC
https://docs.splunk.com/Documentation/Splunk/6.6.1/DistSearch/SHCarchitecture

For deploying apps, you have to push from the Deployer -
http://docs.splunk.com/Documentation/Splunk/6.6.1/DistSearch/PropagateSHCconfigurationchanges

Happy reading!

0 Karma

xsstest
Communicator

There are three members: 2 search head +1 search captain

0 Karma

jharms70
New Member

hi xsstest, warm regards, alert 1

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI xsstest,
only one additional detail: Splunk suggest to use at least three Search Heads and a Deployer in a cluster.
I didn't find where is this information in documentation, but I had a problema on a cluster and Splunk Support said to me that it isn't correct to have only two Search Heads in a cluster.
Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...