Splunk Cloud Platform

Will Add-on Input configuration reflect in both SH's in Victoria?

splunkpri
Explorer

Hi Team,

We have SPlunk Cloud Victoria, We have 2 SH's (Core SH & ES SH) We have installed MS Cloud Service Add-on on Core SH and it is automatically reflecting on ES SH but we have configured input in this Add-on on Core SH but it is not reflecting on ES SH.

1. So Input(MSCS-Addon) configuration also reflecting in both SH's if we configured only on one SH's?

2. If not then we configured input(MSCS-Addon) on both SH's is it possible to get duplicate data?

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Correct on all counts.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

splunkpri
Explorer

Thank you for your Response & support

0 Karma

splunkpri
Explorer

Any reference link is there?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I expected inputs to be documented among other features needing configuration at https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Admin/PrivateApps#How_self-service_app_in... , but don't see it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's a known "feature" of Victoria that uploaded apps are automatically installed on all search heads. It's then up to the user to enable or disable inputs on each search head such that only one of them is enabled. This will avoid duplicate data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunkpri
Explorer

Thank you Richgalloway.

so it’s means input will not automatically replicated in both SH’s if we configured in only one SH’s? only installation will replicate right?

And if we enabled input on both SH’s so there are chances of duplication of data right?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct on all counts.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...