Splunk Search

SHC update apps

TheBravoSierra
Path Finder

I run a search head cluster with Splunk Enterprise. Typically I update apps via the back end CLI, but am wondering if I can update via the GUI. My question is: does the GUI >> Manage Apps >> Find App >> Click "Update App to #.##" update the apps on all of my search heads or only on the one I am viewing? I've always been told to go through the cli so never have attempted this. 

Thanks.

 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You've been told to use the CLI because that is the way that works.  Using the GUI affects only the local SH and can get the cluster out of sync.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You've been told to use the CLI because that is the way that works.  Using the GUI affects only the local SH and can get the cluster out of sync.

---
If this reply helps you, Karma would be appreciated.

gcusello
SplunkTrust
SplunkTrust

Hi @TheBravoSierra,

in a Search Head Cluster you shouldn't have in the Settings menu the choice to manage and update apps, if you have, check your configurations!

Anyway, in a Search Head Cluster, you have to update apps only using the Deployer, if few words it's its own role and almost the one!

To update apps in a Search Head Cluster follow the steps at https://docs.splunk.com/Documentation/Splunk/8.2.2/DistSearch/PropagateSHCconfigurationchanges

Ciao.

Giuseppe

TheBravoSierra
Path Finder

Thanks gcusello!

I will continue using the deployer. For my reference,  what is the config that disables the manage/update apps on a search head cluster member?

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @TheBravoSierra,

i you try to configure an app in a Search Head Cluster using the gui, you have an error and you cannot.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...