Splunk Enterprise

Need help with Deploying Apps or TAs using Deployment server in Linux environment please. Need details please.

SamHTexas
Builder

Need help with Deploying Apps or TAs using Deployment server in Linux environment please. I greatly appreciate your help. I have tried my notes, but not good enough for the job. Thx

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please be more specific.  What problem are you having?  What exactly are you trying to do and how exactly are you trying to do it?  What errors do you get?  Have you read the manuals?

---
If this reply helps you, Karma would be appreciated.
0 Karma

SamHTexas
Builder

Thank u for reaching out my good friend. We have Splunk & ES in a large environment. I am trying to deploy new Splunk Apps or TAs (New Apps) or New TAs via the Deployment server that I have learned is the proper method. So that the Apps are properly copied to Master cluster server & the Deployment server & Indexes. I would like to use the DS server at time install a new App or TA to a certain server for example Server123. If I have made sense so far. Later on  I will use this new method of installing Apps or TAs to install new version of over 60 Apps or TAs to override the older version of them in our environment. I thank u so much. I owe you lunch for  2 weeks when you visit Austin TX area. 

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Use the DS for deploying apps to forwarders and unclustered indexers.  Use the CM for deploying apps to clustered indexers.  Do NOT use the DS for clustered indexers.  Use the SHC Deployer for a SHC.  Yes, it's three different places where you need to manage apps, but each is different and trying to use a manager in ways it was not intended can bring sadness.

Bear in mind that an app deployed by the DS cannot override a setting in $SPLUNK_HOME/etc/system/local.  This often causes confusion about why a deployed app is not working right. When switching to using a DS, make sure etc/system/local is empty.  Put deploymentclient.conf in an app that is installed before the UF starts.

---
If this reply helps you, Karma would be appreciated.

isoutamo
SplunkTrust
SplunkTrust
And remember to define that UF will be rebooted always after TA has installed on it. Otherwise it will be there, but UF didn't realise and use it before UF has restarted!
Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...