Deployment Architecture

app installation in distribute splunk environment

arun_kant_sharm
Path Finder

Hi Experts,

https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall

I follow the steps given in above link for install app in distributed environment, I installed "Splunk Add on for AWS".
I have 2 search head servers, but using above link its come only on single Search Head, I verified from the back-end.

Is this any fault in my environment setups ? Or I need to copy the same app using linux command to the other Search Head server ?
Or only one env its OK??

0 Karma

richgalloway
SplunkTrust
SplunkTrust

There are several sets of instructions at that link and you didn't say which one you followed. The instructions for a single search head put the app only on that search head. You'll have to repeat the steps for the other SH (unless they're clustered or under a deployment server, but neither was mentioned so I'll assume they don't apply).

Don't forget to install the add-on on your indexers. That's also a separate step.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...