Deployment Architecture

Custom deployment app - separate configs for search heads and forwarders

alekwisnia
Explorer

This is my architecture:

1. A deployment server (DS) with apps within deployment-apps folder

2. Two search heads (SH)

3. Two clustered indexers (CI)

4. A number of production servers with Splunk forwarder installed (SF).

I feed both SH and SF with apps on DS. SF write to CI and SH reads from CI.

I need to develop a custom app to read application logs. I know that I need inputs.conf on SF and props.conf (with i.e. EXTRACT parameter set) on SH. 

What is the best and proper way to do so? Create two separate apps (one for SH and one for SF)? Or use one app, but disable part of config files somehow (i.e. basing on server class)? I don't want inputs.conf to be used on SH and props.conf on SF. What about Splunkbase apps (i.e. for Apache) - how they should be different and how to maintain them?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @alekwisnia,

the best approach, as you can see in Splunkbase, is to create three custom apps:

  • the main app to install on Search Heads, containing all the knowledge object, and the dashboards;
  • a Technical Add-On (TA) containing inputs.con end eventually props.conf to install on Universal Forwarders;
  • a TA for Indexers containing indexers.conf, props.conf and transforms.conf.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...