Hi,
i developed an addon for Splunk ES. In a clusterized environment, where do I have to install the addon? In every env where Splunk Es is installed?
It depends on what your addon is doing.
Is it dashboards, user knowledge objects? If yes, generally on the ES SH
Is it doing search time extractions and CIM mapping? If yes, on the ES SH
Is it doing line / event breaking, parsing? If yes, on the Indexers
Based on those, you can determine where it should be placed.
It depends on what your addon is doing.
Is it dashboards, user knowledge objects? If yes, generally on the ES SH
Is it doing search time extractions and CIM mapping? If yes, on the ES SH
Is it doing line / event breaking, parsing? If yes, on the Indexers
Based on those, you can determine where it should be placed.
thanks! very clear!
If you write a TA you think is useful, please release it on apps.splunk.com.
There's a good chance others would find it useful.
we will 🙂