Knowledge Management

Do i need to install an APP onto search peers?

robertlynch2020
Influencer

Hi

Do i need to install an APP onto search peers?

If so, What is the best approach to get an APP(That i update daily) on to search peers(Indexers, Non Clustered).

So i am setting up one Search head and 2 Indexers, I think i have to install the APP onto the search peers, if so how can i manage this, as i will update them daily on my Search Head?

Regards
Robert

0 Karma
1 Solution

Vijeta
Influencer

@robertlynch2020 What is the app ? You do not need to set up or update the app on Indexers.

View solution in original post

0 Karma

Vijeta
Influencer

@robertlynch2020 What is the app ? You do not need to set up or update the app on Indexers.

0 Karma

robertlynch2020
Influencer

The apps had a lots of datamodels, so i am trying to understand how it works.

If i don't install the apps on to the indexers and the forwarders send the data just to the indexers (not the search head), how does it know what is the structure of the datamodels for acceleration

0 Karma

Vijeta
Influencer

The datamodel acceleration creates file on indexers in the below directory. This path can be configured on your indexers in indexes.conf . It does not need to know any structure, when you accelerate datamodel on search head the results will be sent to indexers in below directory.
volume:_splunk_summaries/$_index_name/datamodel_summary

0 Karma

robertlynch2020
Influencer

Thanks for the replay.

So, i dont need to do anything - this is under the hood for me?

0 Karma

Vijeta
Influencer

Unless the app documentation says it to be installed to Search head and indexers and or Heavy forwarders due to CIM or tags etc.
Which app is it?

0 Karma

robertlynch2020
Influencer

I have created the app.

0 Karma

Vijeta
Influencer

Then you don't need to do anything on indexers, except defining index.

0 Karma

robertlynch2020
Influencer

ok thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...