Splunk Enterprise Security

splunk add-on installation on deployment server- commands/installation setups on linxes server CLI commands

kiranhar
Explorer

I need to install an updated app on the deployment server, please provide me the steps/commands to install the add-on ( updated app) on the deployment server and then push to other Splunk instances. I am getting the following error when I try to install the updated app on search head directly,

There was an error processing the upload.app=Splunk_TA_juniper is already managed via deployment client; it may not be overridden via search head cluster deployer, UI, CLI, or REST API; remove existing app=Splunk_TA_juniper via deployment server if you wish to install it via any of these other mechanisms

0 Karma
1 Solution

woodcock
Esteemed Legend

Install the app on the Deployment Server through the GUI and configure it as necessary. Then go to the CLI of the DS and move the app from the .../apps/ directory to the .../deployment-apps/ directory, taking care to merge anything in the current app's .../local/ directory with the new app first. Then restart Splunk on the DS.

View solution in original post

0 Karma

woodcock
Esteemed Legend

Install the app on the Deployment Server through the GUI and configure it as necessary. Then go to the CLI of the DS and move the app from the .../apps/ directory to the .../deployment-apps/ directory, taking care to merge anything in the current app's .../local/ directory with the new app first. Then restart Splunk on the DS.

0 Karma

woodcock
Esteemed Legend

@kiranhar I see in your comment that this worked so do come back and click Accept to close the question.

0 Karma

kiranhar
Explorer

Done. Thanks

0 Karma

lloydknight
Builder

Hello @kiranhar

See this link below:
https://docs.splunk.com/Documentation/Splunk/7.3.1/DistSearch/PropagateSHCconfigurationchanges

You're not supposed to deploy apps directly on a Search Head Cluster using the Deployment Server.

Let me know if this is not the case.

Thanks!

0 Karma

kiranhar
Explorer

Thanks. The search head is not in a cluster. However, I have followed the process suggested by woodcock and my installation goes smooth. I have verified on Splunk relevant instances after that and Splunk add-on is updated everywhere.

0 Karma

lloydknight
Builder

Hello @kiranhar

are you trying to deploy an add-on using Deployment Server on a Search Head Cluster?

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...