All Apps and Add-ons

How to Install Splunk App For Net App ONTAP

BCSITS
Engager

SplunkAppForNetAppONTAP - Deploy this app to $SPLUNK_HOME/etc/apps on your SEARCH HEAD only.

Can someone please explain what is the SEARCH HEAD?
And how do we download, Splunk_TA_ONTAP7, and Splunk_SA_ONTAP_KB

I am quite new to Netapp

Thanks

0 Karma

Kate_Lawrence-G
Contributor

A Splunk setup can be distributed so that your search heads (the GUI that you run your searches through) and the indexers (what crunches the data) can be separated out. It can also be an all-in-one solution that does both.

The Splunk App for NetApp ONTAP has 2 main components:

  1. It has a search head app. This is the GUI side and has the dashboards you use to view the data. This get's downloaded from http://splunk-base.splunk.com/apps/67764/splunk-app-for-netapp-ontap and can be installed through the manager/app section on the search head
  2. Splunk_TA_ONTAP7 is what is called a Technology Addon - it supplies the indexing logic needed to make the data collected (in this case from the NetApp) searchable and useful for the dashboards. It has the props.conf and transforms.conf that are needed to manipulate the data. In a distributed environment this would sit at the indexer, but in an all-in-one solution it can be installed within the apps directory as well.

You need both of these to make the application work correctly.

Kate_Lawrence-G
Contributor

I believe the add-ons come as part of the package - check the /opt/splunk/etc/apps directory and see what's in there?

0 Karma

BCSITS
Engager

Hi, Thanks for the Info Kate.

I have now installed SplunkApp

but where can i download the SPlunk Addons?
and how do I install them?

appreciate hour help..

Thanks

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...