Splunk Search

Configs for mgmt consoles...

a212830
Champion

Hi,

Where/how do the Splunk management consoles get their configs? For example, the IDX get them from the CM, the SH from the deployer...

If I want to adjust settings for the CM, DMC, Deployment server, - where do I do it? Directly on them? My DMC, for example - where do I set it's license manager?

0 Karma

sloshburch
Ultra Champion

Have a license client app which defines such config. Have that deployed to all instances (except forwarders maybe) other than the license server. That means the utility servers are deployment clients of the deployment server. The DS can be assigned this app with a cd $SPLUNK_HOME/etc/apps && sym link ln -fs ../deployment-apps/license_client.

You can extend this to other config as well. In fact, I have a global app that changes ports etc..., a forwarding app, a search head app (that enables the web ui - which is disabled otherwise), and so forth. More specific apps give you more control to push out such config to the utility instances.

0 Karma

dshpritz
SplunkTrust
SplunkTrust

For non-clustered items (search heads, heavy forwarders, DMC, deployment server), you can use the command line, config files, or GUI (for most items). Any full instance of Splunk should have its license master set. Some examples:

http://docs.splunk.com/Documentation/Splunk/6.3.3/Admin/Configurealicenseslave

http://docs.splunk.com/Documentation/Splunk/latest/Admin/LicenserCLIcommands

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...