Monitoring Splunk

Machine learning toolkit performance impacts on the cluster

nawazns5038
Builder

Hi,

For installing the Machine Learning Toolkit on a search head cluster, are there any impacts on the performance of the cluster.
Is it necessary to install the addon on the indexer cluster as well.

0 Karma

adonio
Ultra Champion

hello there:

per docs:
http://docs.splunk.com/Documentation/MLApp/3.1.0/User/Installandconfigure#Distributed_deployment
you have to have Splunk 6.4 or greater for leveraging ML toolkit on SHC
regarding Indexer Cluster, same doc link.
"install Python for Scientific Computing on the indexers in your cluster. This feature is disabled by default."

hope it helps

0 Karma

nawazns5038
Builder

Hi,

Is it a must to install the addon on the indexer cluster .

Problem replicating config (bundle) to search peer '10.x.x.xx.xx:8089', error while transmitting bundle data.

I am getting that error on the search head after I enable the app on the search head without an addon on the indexer cluster. How can this be resolved and why is the bundle being pushed to the indexers while I install in the search head .

Thanks,
N

0 Karma

adonio
Ultra Champion

according to the link in the answer, "If you want to use the distributed apply feature of the Splunk Machine Learning Toolkit, install Python for Scientific Computing on the indexers in your cluster.
not sure what add-o regarding the error, or why bundles pushed to indexers while you install on SH.
if you have a SHC - install on Deployer and push to members

0 Karma

nawazns5038
Builder

I just found this link and you can go through it .

http://docs.splunk.com/Documentation/Splunk/6.3.1/DistSearch/Whatsearchheadssend

It does not say that it is mandatory to install on indexers . I'll try installing the addon on the indexers and check back for errors.

0 Karma

adonio
Ultra Champion

please pay attention to splunk versions and the docs versions...

0 Karma

nawazns5038
Builder

yes, our search head is 6.5.3 .. and the same doc all versions

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...