Splunk Enterprise Security

How to create custom app/addon(steps) using CLI and push to SHC members using deployer

obais9346
Engager

I am a Advanced beginner to splunk and i want to create custom app/addon in my search head cluster environment and push via deployer to all shc members

Note: We have GUI disabled in our environment to create apps/addons through shc members

Also how can i place app and tar and untar app/addon in shcluster/apps directory and push to shc members via deployer.

Please help with steps for best practice

0 Karma
1 Solution

aasabatini
Motivator

Hi @obais9346 

  I suggest to use this very helpful app "Splunk add-on builder" and try the apps or add-on on a test enviroment.

https://splunkbase.splunk.com/app/2962/

When you tested your add-on or app you can put on the Deployer  in $Splunk_Home/etc/shcluster/apps directory, so you need to manually copy the app to that directory. 

run this comand

 

 

splunk apply shcluster-bundle -target <URI>:<management_port> -auth <username>:<password>

 

 

for more details there is the documentation

https://docs.splunk.com/Documentation/Splunk/8.1.3/DistSearch/PropagateSHCconfigurationchanges

let me know if you need more informations

Alessandro

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”

View solution in original post

Tags (2)

obais9346
Engager

Thanks helped me

0 Karma

obais9346
Engager

Thank you for this information, but i have read this document, i am mainly looking for creating app/addon(installing on search head members) and deploying via CLI through deployer without add on builder.

 

https://docs.splunk.com/Documentation/Splunk/8.1.3/DistSearch/PropagateSHCconfigurationchanges

 

i have read this too

appreciate your help 

0 Karma

aasabatini
Motivator

Hi @obais9346 

  I suggest to use this very helpful app "Splunk add-on builder" and try the apps or add-on on a test enviroment.

https://splunkbase.splunk.com/app/2962/

When you tested your add-on or app you can put on the Deployer  in $Splunk_Home/etc/shcluster/apps directory, so you need to manually copy the app to that directory. 

run this comand

 

 

splunk apply shcluster-bundle -target <URI>:<management_port> -auth <username>:<password>

 

 

for more details there is the documentation

https://docs.splunk.com/Documentation/Splunk/8.1.3/DistSearch/PropagateSHCconfigurationchanges

let me know if you need more informations

Alessandro

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
Tags (2)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...