Splunk ITSI

Replicate tags.conf between search heads

genesiusj
Builder

Hello,

We have a search head cluster and an ITSI instance.

How do we replicate the tags.conf files from various apps on the SHC to ITSI? These are needed for running the various module searches, and other ITSI macros.

Did someone create an app to handle this?

Thanks and God bless,
Genesius

Labels (2)
0 Karma

genesiusj
Builder

Apologies. I did not see any notification in my email about this question receiving responses.

I am moved from project to project, and this one is now on hold.

@PrewinThomas and @livehybrid  I gave you some karma.

God bless.

0 Karma

PrewinThomas
Motivator

@genesiusj 

Standalone ITSI and Search Head Clusters (SHC) do not automatically share knowledge objects. To ensure your ITSI instance has the necessary tags, you must manually install the required apps or deploy them via the Deployment Server.

Alternatively, you can create a custom app containing all your knowledge objects and deploy it to both your SHC and ITSI environments. This approach ensures consistency and simplifies management across both platforms.


Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

livehybrid
SplunkTrust
SplunkTrust

Hi @genesiusj 

If your ITSI instance is separate to the SHC then there is no built-in feature that would replicate between the SHC and ITSI. 

There are a number of apps on Splunkbase that do various knowledge object management but I havent personally seen any that do this.

How do you currently manage your tags.conf on the SHC? If these are managed on a search-head deployer and pushed to the SHC then you can install the same app on the ITSI SH (via appropriate deployment mechanism) but you do then have to ensure you push this out to ITSI when making changes to the app which is deployed to SHC.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...