Knowledge Management

Do i need to install an APP onto search peers?

robertlynch2020
Influencer

Hi

Do i need to install an APP onto search peers?

If so, What is the best approach to get an APP(That i update daily) on to search peers(Indexers, Non Clustered).

So i am setting up one Search head and 2 Indexers, I think i have to install the APP onto the search peers, if so how can i manage this, as i will update them daily on my Search Head?

Regards
Robert

0 Karma
1 Solution

Vijeta
Influencer

@robertlynch2020 What is the app ? You do not need to set up or update the app on Indexers.

View solution in original post

0 Karma

Vijeta
Influencer

@robertlynch2020 What is the app ? You do not need to set up or update the app on Indexers.

0 Karma

robertlynch2020
Influencer

The apps had a lots of datamodels, so i am trying to understand how it works.

If i don't install the apps on to the indexers and the forwarders send the data just to the indexers (not the search head), how does it know what is the structure of the datamodels for acceleration

0 Karma

Vijeta
Influencer

The datamodel acceleration creates file on indexers in the below directory. This path can be configured on your indexers in indexes.conf . It does not need to know any structure, when you accelerate datamodel on search head the results will be sent to indexers in below directory.
volume:_splunk_summaries/$_index_name/datamodel_summary

0 Karma

robertlynch2020
Influencer

Thanks for the replay.

So, i dont need to do anything - this is under the hood for me?

0 Karma

Vijeta
Influencer

Unless the app documentation says it to be installed to Search head and indexers and or Heavy forwarders due to CIM or tags etc.
Which app is it?

0 Karma

robertlynch2020
Influencer

I have created the app.

0 Karma

Vijeta
Influencer

Then you don't need to do anything on indexers, except defining index.

0 Karma

robertlynch2020
Influencer

ok thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...