Splunk Cloud Platform

Will Add-on Input configuration reflect in both SH's in Victoria?

splunkpri
Explorer

Hi Team,

We have SPlunk Cloud Victoria, We have 2 SH's (Core SH & ES SH) We have installed MS Cloud Service Add-on on Core SH and it is automatically reflecting on ES SH but we have configured input in this Add-on on Core SH but it is not reflecting on ES SH.

1. So Input(MSCS-Addon) configuration also reflecting in both SH's if we configured only on one SH's?

2. If not then we configured input(MSCS-Addon) on both SH's is it possible to get duplicate data?

Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Correct on all counts.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

splunkpri
Explorer

Thank you for your Response & support

0 Karma

splunkpri
Explorer

Any reference link is there?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I expected inputs to be documented among other features needing configuration at https://docs.splunk.com/Documentation/SplunkCloud/9.0.2209/Admin/PrivateApps#How_self-service_app_in... , but don't see it.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's a known "feature" of Victoria that uploaded apps are automatically installed on all search heads. It's then up to the user to enable or disable inputs on each search head such that only one of them is enabled. This will avoid duplicate data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

splunkpri
Explorer

Thank you Richgalloway.

so it’s means input will not automatically replicated in both SH’s if we configured in only one SH’s? only installation will replicate right?

And if we enabled input on both SH’s so there are chances of duplication of data right?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct on all counts.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...