Getting Data In

About deployment-apps

nanachu
Path Finder

Hi, all.

I have a cluster environment. (1 search head, 2 indexer)
I want to change the character code of the data.

So, I rewritten and reloaded props.conf of the application under deployment-apps of the cluster master.

But when I look at the splunk answer, it looks different.

https://answers.splunk.com/answers/107512/where-do-i-edit-props-conf-in-a-cluster.html

Why is this answer instead of creating props.conf for apps under deployment-apps?
I understand that I should go through props.conf before indexing, but I can't understand the difference with deployment-apps.

Could you help me?

Thank you.

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Do not use the deployment server (etc/deployment-apps) to send configuration to clustered indexers, use the cluster master (etc/master-apps).

See https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/Manageappdeployment

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @nanachu,
the folder deployment-apps is only to deploy apps using the Deployment Server, the folder to deploy apps in Master Node is master-apps.
You can find more infos at https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/Manageappdeployment

Ciao.
Giuseppe

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Do not use the deployment server (etc/deployment-apps) to send configuration to clustered indexers, use the cluster master (etc/master-apps).

See https://docs.splunk.com/Documentation/Splunk/8.0.0/Indexer/Manageappdeployment

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...