Splunk Enterprise

How to distribute the default app, if I want to do some changes to the default app to the SHC members?

super_saiyan
Communicator

how to distribute the default app, if I want to do some changes  to the default app to the SHC members ?

Tags (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@super_saiyan - It is not recommended to make changes to default apps. Specifically for the SHC environment. I would always avoid it.

You can create a custom App, and put your configuration, dashboard, alert, etc in that instead.

Is there any specific requirement to make changes to the default App? In most cases, you should be able to apply the above resolution.

------
I hope this helps!!!

super_saiyan
Communicator

but how do you distribute ? can give me some step by step process

in search head clustering to search head clustering member.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Please read this documentation section https://docs.splunk.com/Documentation/Splunk/8.2.6/DistSearch/HowconfigurationworksinSHC especially this document https://docs.splunk.com/Documentation/Splunk/8.2.6/DistSearch/PropagateSHCconfigurationchanges

There is quite a lot going on with using deployer on SHC so it's important that you understand it.

super_saiyan
Communicator

is it possible to distribute from Deployer of the default app ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

It's strongly guided to really don't do it, as this normally leads unusable SHC cluster default app and probably also some other issues. 

As other already said, please create your own "Default" app where users should create their KO's etc. and then deploy to it as needed. Even better is create several Apps for them based on your business systems etc. Give to those access by roles and you will get better granularity for security and access to those KOs.

r. Ismo

Get Updates on the Splunk Community!

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...