Splunk Enterprise Security

Unable to deploy Enterprise Security add-ons to Indexers

cemiam
Path Finder

Hi,

I have 1 SH and 3 clustered indexers. I have installed Enterprise Security to SH and follow workaround to deploy add-ons to indexers. I have downloaded Splunk_TA_ForIndexers from the Enterprise Security and upload it under $SPLUNK_HOME/etc/master-apps on SH which is also configured as cluster master. Then hit Validate and Check Restart under Index Clustering > Edit > Configuration Bundle Actions but it didn't find anything to deploy. Active Bundle ID and Latest Bundle ID seems the same. What should I do to overcome such an issue?

Best Regards,

0 Karma

mayurr98
Super Champion
0 Karma

cemiam
Path Finder

Hi,

I am following this Create the "Splunk_TA_ForIndexers and manage deployment manually" procedure on link below. I have downloaded Splunk_TA_ForIndexers placed it under $SPLUNK_HOME/etc/master-apps on the Search Head.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...