All Apps and Add-ons

Where to install Splunkgit in a distributed environment?

j4adam
Communicator

I can't find any documentation regarding the best deployment scheme for this. Looking at the configs I'm thinking:

  • Install it on a Heavy Forwarder and configure that to have the hooks into the repos
  • Install it on Indexers (or at least the indexes.conf file) so the data gets indexed. I don't see any index time opertations.
  • Install it on Search Heads in order to make use of the views, etc

Any thoughts? Am I correct in my assessment?

Side note: The Splunkgit tag is not recognized in the "tag" search on the sidebar.

0 Karma

jagadeeshm
Contributor

You seem to be on the right track. But you still need to know couple of things -

  1. If you are planning to use Heavy Forwarder for your input, it should already be configured to send all data to the indexers. And yes, you need to remove the indexes.conf file from the Heavy Forwarder.
  2. If the App provides in-built dashboards/panels, you may want to install it on the Search Head to use their UI. But when you install it on Search Head, it is recommended to eliminate some of the files like - inputs.conf, indexes.conf etc. Please see here for details instructions - http://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall
  3. Your are right! Index time operations are not always required to index data.
0 Karma

j4adam
Communicator

Would I actually need to remove the indexes.conf file from from the heavy forwarder? I have indexing globally disabled. AFAIK leaving it there would serve no purpose, but would also cause no harm.

0 Karma

jagadeeshm
Contributor

Well there are 2 things -

1 - If you enabled ALL data forwarding from HF to Indexers, you don't have to worry about having the indexes.conf on HF. On the other hand if the forwarding is not enabled, you would end up indexing data in HF (which you probably don't want)

2 - If the App has a UI for defining the inputs, and if you are planning to use it, you may need the indexes.conf.

Hope that helps.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...