Splunk Cloud Platform

Will Add-on Input configuration reflect in both SH's in Victoria?

splunkpri
Explorer

Hi Team,

We have SPlunk Cloud Victoria, We have 2 SH's (Core SH & ES SH) We have installed MS Cloud Service Add-on on Core SH and it is automatically reflecting on ES SH but we have configured input in this Add-on on Core SH but it is not reflecting on ES SH.

1. So Input(MSCS-Addon) configuration also reflecting in both SH's if we configured only on one SH's?

2. If not then we configured input(MSCS-Addon) on both SH's is it possible to get duplicate data?

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Correct on all counts.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

splunkpri
Explorer

Thank you for your Response & support

0 Karma

splunkpri
Explorer

Any reference link is there?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I expected inputs to be documented among other features needing configuration at https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Admin/PrivateApps#How_self-service_app_in... , but don't see it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's a known "feature" of Victoria that uploaded apps are automatically installed on all search heads. It's then up to the user to enable or disable inputs on each search head such that only one of them is enabled. This will avoid duplicate data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunkpri
Explorer

Thank you Richgalloway.

so it’s means input will not automatically replicated in both SH’s if we configured in only one SH’s? only installation will replicate right?

And if we enabled input on both SH’s so there are chances of duplication of data right?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct on all counts.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...