Deployment Architecture

Deployment server: How to handle a single add-on with multiple configuration versions?

ikulcsar
Communicator

Hi,

I have to manage multiple UF agent with a single deployment server.
I have to set up different whitelist/blacklist for different server classes. For example, I have to collect events with different EventID from the DCs and from the other Win servers. So I have to assign the Splunk_TA_windows add-on to ServersClassA and ServerClassB, but with different inputs.conf.

How can I do this? Is it safe to rename the Add-on's directory to Splunk_TA_windows_DC, Splunk_TA_windows_WinSer, etc? This way I can separate the configs.

Regards,
István

0 Karma
1 Solution

FrankVl
Ultra Champion

Do you really need Splunk_TA_Windows on the UFs?

I would check which config you actually need (mostly inputs.conf I guess?) and put that in specific small custom add-ons and deploy that to the relevant UFs.

Even if for some reason you would need Splunk_TA_Windows deployed, you could still do that but keep the custom configuration in separate apps. I wouldn't really recommend using multiple (renamed) copies of the same off-the-shelve TA, that is going to be hard to maintain.

View solution in original post

0 Karma

FrankVl
Ultra Champion

Do you really need Splunk_TA_Windows on the UFs?

I would check which config you actually need (mostly inputs.conf I guess?) and put that in specific small custom add-ons and deploy that to the relevant UFs.

Even if for some reason you would need Splunk_TA_Windows deployed, you could still do that but keep the custom configuration in separate apps. I wouldn't really recommend using multiple (renamed) copies of the same off-the-shelve TA, that is going to be hard to maintain.

0 Karma

ikulcsar
Communicator

Hi,

As far as I know, Splunk_TA_Windows contains WinEventLog://* input stanzas. Unfortunately, I don't know Splunk systems in details yet.

So, in general, I can use the default Splunk_TA_Windows on all server, and create some custom add-on with the specific config(inputs.conf) and push them alongside with the default Splunk_TA_Windows add-on?

Regards,
István

0 Karma

FrankVl
Ultra Champion

Yes.

But once more: I don't think you really need the full TA on your UFs, since that TA (apart from the inputs.conf) mostly consists of index time and search time stuff, which your UF won't handle, the TA needs to be on your indexer(s) (or the first HF that exist between your UF and Indexers) and on your search head(s).

0 Karma

ikulcsar
Communicator

Thank you. I understand it, so far, I was on the safe side, use the whole add-on everywhere, I did not feel the Force in me to select which file needed, which doesn't. (And guide says Install the add-on...)

Regards,
István

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...