Deployment Architecture

How to create a splunk query that will list the applications on the members of the search head cluster?

pc1234
Engager

i need a splunk query that will the list the applications on each member of the search head cluster. i am running the query on the deployer.
I've cant find a REST command or a splunk internal query to list the apps.

Any assistance is appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There is a REST command to list the apps on a local instance, but I have not found one to do the same for a remote instance. That said, each member of a SHC should have the same apps as those in $SPLUNK_HOME/etc/shcluster/apps on the deployer. I haven't tried it, yet, but you could wrap a script around https://:/services/apps/local to get a list of apps.

Have a look at https://docs.splunk.com/Documentation/Splunk/8.0.1/RESTREF/RESTcluster#Search_head_cluster_endpoints to see if any of those endpoints do what you want. They will have to be run from a cluster member, however, and some from the captain.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Security Highlights | November 2022 Newsletter

 November 2022 2022 Gartner Magic Quadrant for SIEM: Splunk Named a Leader for the 9th Year in a RowSplunk is ...

Platform Highlights | November 2022 Newsletter

 November 2022 Skill Up on Splunk with our New Builder Tech Talk SeriesCan you build it? Yes you can! *play ...

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...