Installation

Where to install an app?

bkcarter
Path Finder

One of the challenges I am finding with Splunk is WHERE to install the different pieces. I have an environment with Indexer, Search Heads, multiple forwarders of various types including Universal Forwarders. Where would this app Splunk for Unix/Linux) be installed at? Search Head? Indexer? All of the above? Please clarify for me. Thanks

Tags (1)

BobM
Builder

The simple answer is the main app "Splunk for Unix and Linux" goes on the search head and "Splunk for Unix and Linux technology add-on" goes on the indexers and any forwarders collecting Unix/Linux data.

malmoore
Splunk Employee
Splunk Employee

Hi Bkcarter (and sowings):

We're updating the Unix app documentation to help reduce confusion and the presumption that Unix App users will automatically know where everything goes. The next version of the Unix App docs will have extensive information on how to deploy the app in distributed environments, cross-platform compatibility, and more. This version will initially get deployment location info.

While we can't possibly document every potential use case for these apps and add-ons, your feedback helps us ensure that the most relevant ones have representation.

0 Karma

sowings
Splunk Employee
Splunk Employee

And the Windows app complains when it's run on a Linux search head! You can safely ignore that error (and rest assured that it's going away when the apps are updated).

The general rule is that a "Technology Add-On" may contain rules for parsing and / or data collection, and will therefore need to go on non search head machines (that would include indexers and forwarders, such as user desktops).

The app itself will search against the data collected by the TA to provide meaning from the content.

The application README should (hopefully) spell this out.

0 Karma

bkcarter
Path Finder

Thank you. I can find a lot of documentation on Apps and add-ons, but I have yet to see something that explains what should go where and why. One of the challenges with Splunk is that it is so flexible, and all of the documentation just assumes that you know where everything goes.

So my Search Head is a Windows machine and my Indexer is Linux. When I install the app on the Head it complains that it is not a Linux box. This confuses me even more.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...