Deployment Architecture

How to update the search head configuration from the cluster master?

mciudad
Explorer

I'm trying to update the configuration of all the peers from my cluster master. With the indexers, it's eash to put the configuration file in $SPLUNK_HOME/etc/slave_apps/_cluster/local and then the indexer receives it, but I can't find any way to update the search head. Is there any similar (or not similar) way of doing it?

Thank you.

0 Karma
1 Solution

ppablo
Retired

Hi @mciudad

If you're trying to update configurations for search heads in a search head cluster, you should be using the Deployer instance to push changes. Check out this page from Splunk documentation covering how to configure the Deployer and how to push a configuration bundle to the search head cluster members.
http://docs.splunk.com/Documentation/Splunk/6.2.3/DistSearch/PropagateSHCconfigurationchanges

View solution in original post

ppablo
Retired

Hi @mciudad

If you're trying to update configurations for search heads in a search head cluster, you should be using the Deployer instance to push changes. Check out this page from Splunk documentation covering how to configure the Deployer and how to push a configuration bundle to the search head cluster members.
http://docs.splunk.com/Documentation/Splunk/6.2.3/DistSearch/PropagateSHCconfigurationchanges

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...