Splunk ITSI

Replicate tags.conf between search heads

genesiusj
Builder

Hello,

We have a search head cluster and an ITSI instance.

How do we replicate the tags.conf files from various apps on the SHC to ITSI? These are needed for running the various module searches, and other ITSI macros.

Did someone create an app to handle this?

Thanks and God bless,
Genesius

Labels (2)
0 Karma

genesiusj
Builder

Apologies. I did not see any notification in my email about this question receiving responses.

I am moved from project to project, and this one is now on hold.

@PrewinThomas and @livehybrid  I gave you some karma.

God bless.

0 Karma

PrewinThomas
Motivator

@genesiusj 

Standalone ITSI and Search Head Clusters (SHC) do not automatically share knowledge objects. To ensure your ITSI instance has the necessary tags, you must manually install the required apps or deploy them via the Deployment Server.

Alternatively, you can create a custom app containing all your knowledge objects and deploy it to both your SHC and ITSI environments. This approach ensures consistency and simplifies management across both platforms.


Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

livehybrid
SplunkTrust
SplunkTrust

Hi @genesiusj 

If your ITSI instance is separate to the SHC then there is no built-in feature that would replicate between the SHC and ITSI. 

There are a number of apps on Splunkbase that do various knowledge object management but I havent personally seen any that do this.

How do you currently manage your tags.conf on the SHC? If these are managed on a search-head deployer and pushed to the SHC then you can install the same app on the ITSI SH (via appropriate deployment mechanism) but you do then have to ensure you push this out to ITSI when making changes to the app which is deployed to SHC.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...