Getting Data In

Splunk Cloud - How to generate list of deployed apps/TA's on indexers?

random_event
Engager

Using Splunk Cloud and management made the decision to send from UF's straight to Splunk Cloud indexers.  As such, have run into a number of issues with various TA's not deployed to Cloud indexers.  How can I generate a list of deployed aps/TA's that are on the Cloud indexers?

Labels (1)
Tags (3)
0 Karma
1 Solution

tshah-splunk
Splunk Employee
Splunk Employee

Hey @random_event,

Yes, it is possible that the app installed via Self Service doesn't get installed on the indexers. You can run the following search to get list of apps that are installed on Indexers

| rest services/apps/local
| sort title
| stats values(splunk_server) as splunk_server by title
| rename title as app
---
If you find the answer helpful, an upvote/karma is appreciated

View solution in original post

tshah-splunk
Splunk Employee
Splunk Employee

Hey @random_event,

Yes, it is possible that the app installed via Self Service doesn't get installed on the indexers. You can run the following search to get list of apps that are installed on Indexers

| rest services/apps/local
| sort title
| stats values(splunk_server) as splunk_server by title
| rename title as app
---
If you find the answer helpful, an upvote/karma is appreciated

richgalloway
SplunkTrust
SplunkTrust

I would have suggested something similar, but thought it wouldn't work because of "send REST to indexers" being blocked in Splunk Cloud.  Just tried it, however, and it worked.

---
If this reply helps you, an upvote would be appreciated.

richgalloway
SplunkTrust
SplunkTrust

There is no way to see just what is installed on the indexers.  The best you can do is open the Manage Apps screen and see what TAs are installed there.  If the TA is on the SH then it is also installed on the indexers.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

random_event
Engager

That's what I thought, but I just ran into a situation where there was a TA deployed to the Cloud SHC but it was not present on the indexers, hence my inquiry now.

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...