All Apps and Add-ons

Warning - DB Connect is running in SHCluster! Some functions will be disabled under this environment.

saranya_fmr
Communicator
  1. List item

Can this warning be ignored coz I always get this in the SH Cluster. We do not have scheduled inputs and scheduled outputs and thus we did not install the DB Connect app on the Heavy forwarders. We have it only the SH cluster.

But everytime I open the app , I see this warning. So can This be ignored or is there a way to get rid of this? Is it mandatory to install the app on the Heavy Forwarders?

  1. Also , we will use dbxlookup feature, so does this need the app to be installed on the HF?

alt text

Tags (1)
1 Solution

sloshburch
Splunk Employee
Splunk Employee

As far as it is documented, there is no way to hide the message: http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/WhatsnewinSplunkDBConnect#Scheduled_tasks_...

Perhaps an alternative approach is to disable the visibility of the app for non-admins. That way the commands you want to use are available globally but the app itself is invisible other than for admins who know to ignore the message.
Make the app invisible: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Managingappconfigurationsandproperties
Make sure the command have global permissions: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Manageknowledgeobjectpermissions#Make_a...

View solution in original post

sloshburch
Splunk Employee
Splunk Employee

As far as it is documented, there is no way to hide the message: http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/WhatsnewinSplunkDBConnect#Scheduled_tasks_...

Perhaps an alternative approach is to disable the visibility of the app for non-admins. That way the commands you want to use are available globally but the app itself is invisible other than for admins who know to ignore the message.
Make the app invisible: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Managingappconfigurationsandproperties
Make sure the command have global permissions: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Manageknowledgeobjectpermissions#Make_a...

saranya_fmr
Communicator

Thankyou Burch 🙂

0 Karma

sloshburch
Splunk Employee
Splunk Employee

NP! If you found that satisfactory, then please mark it as an accepted answer so others who stumble on this question will see there is a potential solution. If not, then leave it as is of course.

0 Karma

nawazns5038
Builder

I guess if we keep an app as invisible, it goes invisible to every role including admin as well.

0 Karma

sloshburch
Splunk Employee
Splunk Employee

Hmmm. I think it depends on if you removed the read permission for that role...

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...