Installation

Search Head Cluster Deployer doesn't push ITSI apps

aguilard
Explorer

Hello,

I'm trying to install Splunk ITSI 4.17.1 in a Search Head Cluster with Splunk Enterprise 9.1.2.

I already extract the .spl in the directory $SPLUNK_HOME$/etc/shcluster/apps but when I execute the command splunk apply shcluster-bundle it shows that it has deployed everything correctly but when I go to the Search  Heads none of the ITSI apps are deployed.

i just made a test deploying another simple app just for testing purposes and it worked.

Do you have any idea?

Labels (2)
0 Karma
1 Solution

aguilard
Explorer

Ciao @gcusello ,

Maybe I didn't explain myself correctly. I meant that when the deployer moves the apps to /opt/splunk/var/run/splunk/deploy/apps it created the apps with "-local" But i just discovered that it was for a misconfiguration in the app.conf file deploy mode.

I already fixed it and now  the SHs have all the ITSI apps on the etc/apps directory.

But I'm facing a new problem, when I start ITSI I got this message

aguilard_0-1702467320586.png


But it has no sense because it is the first installation...

Thanks for your response and time

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aguilard,

have you error messages on the Deployer?

have you enough disk space on the Deployer? it's required some additional disk space on it.

what's the owner of the folders and files? it must be splunk.

Which user are you using to install and run splunk?

Ciao.

Giuseppe

0 Karma

aguilard
Explorer

Hello @gcusello ,

I do not have error messages on the Deployer.

I have plenty of space in the disk of the Deployer, I already checked.

The owner of the files is splunk and it's been installed and ran with user Splunk.

The thing that I noticed 20 minutes ago and I do not why is when the deployer pushes the ITSI apps to /opt/splunk/var/run/splunk/apps it adds at the of the folder the word "-local" and I just checked that in other installations that I manage it doesn't occur.

Thanks for the response

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aguilard,

this path isn't correct, check if you configured in serverclasses.conf the targetRepositoryLocation parameter that's used to  configure where to push apps, default is $SPLUNK_HOME/etc/apps.

Ciao.

Giuseppe

0 Karma

aguilard
Explorer

Ciao @gcusello ,

Maybe I didn't explain myself correctly. I meant that when the deployer moves the apps to /opt/splunk/var/run/splunk/deploy/apps it created the apps with "-local" But i just discovered that it was for a misconfiguration in the app.conf file deploy mode.

I already fixed it and now  the SHs have all the ITSI apps on the etc/apps directory.

But I'm facing a new problem, when I start ITSI I got this message

aguilard_0-1702467320586.png


But it has no sense because it is the first installation...

Thanks for your response and time

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aguilard,

it's avery strange behavior: open a cae t sSplunk Support.

Ciao.

Giuseppe

aguilard
Explorer

I fixed the problem simply restarting the cluster and I worked 🙂

Thanks 🙂

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @aguilard,

good for you, see next time!

let me know if I can help you more, or, please, accept one answer for the other people of Community.

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...