Deployment Architecture

Is it possible to use SH-Deployer to Push User (Local) App?

morethanyell
Builder

Basically what I wish to do is very simple, I want to clone 70+ alerts (entire savedsearches.conf). I maybe naive but my plan is to clone them all but not via UI. How can I copy the entire savedsearches.conf we have in ../etc/apps/<appname>/default/savedsearches.conf into our SH deployer and let it apply cluster bundel into the ../etc/users/<username>/<appname>/local/ of our 14 search heads?

0 Karma
1 Solution

tiagofbmm
Influencer

SH Deployer deploys to apps folder only. If you want to push savedsearches to belong privately to users, I'd recommend using Ansible or other automation tool, which would be pretty simple to create there.

View solution in original post

tiagofbmm
Influencer

SH Deployer deploys to apps folder only. If you want to push savedsearches to belong privately to users, I'd recommend using Ansible or other automation tool, which would be pretty simple to create there.

morethanyell
Builder

Hi @tiagofbmm please convert your comment to answer as it directly answers my question. I will accept it. By the way, thank you very much.

0 Karma

tiagofbmm
Influencer

You're welcome. It is converted now 😉

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...