Splunk Search

SHC update apps

TheBravoSierra
Path Finder

I run a search head cluster with Splunk Enterprise. Typically I update apps via the back end CLI, but am wondering if I can update via the GUI. My question is: does the GUI >> Manage Apps >> Find App >> Click "Update App to #.##" update the apps on all of my search heads or only on the one I am viewing? I've always been told to go through the cli so never have attempted this. 

Thanks.

 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You've been told to use the CLI because that is the way that works.  Using the GUI affects only the local SH and can get the cluster out of sync.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You've been told to use the CLI because that is the way that works.  Using the GUI affects only the local SH and can get the cluster out of sync.

---
If this reply helps you, Karma would be appreciated.

gcusello
SplunkTrust
SplunkTrust

Hi @TheBravoSierra,

in a Search Head Cluster you shouldn't have in the Settings menu the choice to manage and update apps, if you have, check your configurations!

Anyway, in a Search Head Cluster, you have to update apps only using the Deployer, if few words it's its own role and almost the one!

To update apps in a Search Head Cluster follow the steps at https://docs.splunk.com/Documentation/Splunk/8.2.2/DistSearch/PropagateSHCconfigurationchanges

Ciao.

Giuseppe

TheBravoSierra
Path Finder

Thanks gcusello!

I will continue using the deployer. For my reference,  what is the config that disables the manage/update apps on a search head cluster member?

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @TheBravoSierra,

i you try to configure an app in a Search Head Cluster using the gui, you have an error and you cannot.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...