Dashboards & Visualizations

Search Head Cluster custom mod alert html replication?

annmarienorcros
Loves-to-Learn Everything

I am trying to get our Add-on that was developed for standalone Splunk to work in a SHC environment.

The Add-on takes input from the user in a setup view and saves the configuration values via the REST API using the Splunk JS SDK.  I am able to replicate  our sa_our_app.conf by adding this stanza in server.conf:

[shclustering]
conf_replication_include.sa_our_app = true

We are able to replicate the setup view in the UI across the search  head members.

The Add-on also uses a custom REST endpoint during setup to write the modular alert html (stored in /data/ui/alert).  Is there a way to replicate this html across all members of the SHC?

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...