Splunk Enterprise Security

Unable to deploy Enterprise Security add-ons to Indexers

cemiam
Path Finder

Hi,

I have 1 SH and 3 clustered indexers. I have installed Enterprise Security to SH and follow workaround to deploy add-ons to indexers. I have downloaded Splunk_TA_ForIndexers from the Enterprise Security and upload it under $SPLUNK_HOME/etc/master-apps on SH which is also configured as cluster master. Then hit Validate and Check Restart under Index Clustering > Edit > Configuration Bundle Actions but it didn't find anything to deploy. Active Bundle ID and Latest Bundle ID seems the same. What should I do to overcome such an issue?

Best Regards,

0 Karma

mayurr98
Super Champion
0 Karma

cemiam
Path Finder

Hi,

I am following this Create the "Splunk_TA_ForIndexers and manage deployment manually" procedure on link below. I have downloaded Splunk_TA_ForIndexers placed it under $SPLUNK_HOME/etc/master-apps on the Search Head.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...