Deployment Architecture

Distribute configuration files across nodes in indexer cluster

rajeev_ku
Path Finder

I Have a PoC environment consist - indexer cluster, SHC, deployment server, forwarder.

I have to deploy configuration files across indexer, any sort and simple way to configure.

Thanks
Rajeev

0 Karma
1 Solution

pradeepkumarg
Influencer

You can distribute apps/configuration files to your indexers using Cluster Master. Put the required apps under $SPLUNK_HOME/etc/master-apps on the cluster master and apply cluster bundle to push the apps to all the peers.

More information in below document

http://docs.splunk.com/Documentation/Splunk/6.4.3/Indexer/Manageappdeployment
http://docs.splunk.com/Documentation/Splunk/6.4.3/Indexer/Updatepeerconfigurations

View solution in original post

pradeepkumarg
Influencer

You can distribute apps/configuration files to your indexers using Cluster Master. Put the required apps under $SPLUNK_HOME/etc/master-apps on the cluster master and apply cluster bundle to push the apps to all the peers.

More information in below document

http://docs.splunk.com/Documentation/Splunk/6.4.3/Indexer/Manageappdeployment
http://docs.splunk.com/Documentation/Splunk/6.4.3/Indexer/Updatepeerconfigurations

rajeev_ku
Path Finder

Thanks a lot.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

If you have an indexer cluster, you also need to have a cluster master. Indexer peer nodes get their configuration from the cluster master. This documented here.

rajeev_ku
Path Finder

Yes, i have deployed master server as well.

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...

Splunk Lantern | Getting Started with Edge Processor, Machine Learning Toolkit ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...