Splunk Cloud Platform

Will Add-on Input configuration reflect in both SH's in Victoria?

splunkpri
Explorer

Hi Team,

We have SPlunk Cloud Victoria, We have 2 SH's (Core SH & ES SH) We have installed MS Cloud Service Add-on on Core SH and it is automatically reflecting on ES SH but we have configured input in this Add-on on Core SH but it is not reflecting on ES SH.

1. So Input(MSCS-Addon) configuration also reflecting in both SH's if we configured only on one SH's?

2. If not then we configured input(MSCS-Addon) on both SH's is it possible to get duplicate data?

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Correct on all counts.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

splunkpri
Explorer

Thank you for your Response & support

0 Karma

splunkpri
Explorer

Any reference link is there?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I expected inputs to be documented among other features needing configuration at https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Admin/PrivateApps#How_self-service_app_in... , but don't see it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's a known "feature" of Victoria that uploaded apps are automatically installed on all search heads. It's then up to the user to enable or disable inputs on each search head such that only one of them is enabled. This will avoid duplicate data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunkpri
Explorer

Thank you Richgalloway.

so it’s means input will not automatically replicated in both SH’s if we configured in only one SH’s? only installation will replicate right?

And if we enabled input on both SH’s so there are chances of duplication of data right?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct on all counts.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...