All,
I have a threat intelligence application installed on my Splunk Cloud. I recently brought online Splunk enterprise security. Why is it that the application is not installed on Splunk Enterprise Security automatically? Shouldn't it replicate over automatically?
ES search heads are fully independent of other search heads. Apps do not replicate between them because of the heavy resource use by ES. Any apps you want on ES have to be installed there.
ES search heads are fully independent of other search heads. Apps do not replicate between them because of the heavy resource use by ES. Any apps you want on ES have to be installed there.