All Apps and Add-ons

Where do I install the Splunk App for Web Analytics in a distributed search environment?

dangchuan
Engager

I have a search head, indexer, and several web servers and run as forwarders. Where do I install this app?

bandit
Motivator

I'd like to see an answer from the author on this as well. It's obvious that a lot of thought has been put into this app since it uses eventtypes, datamodels and kv stores. I would be great if @jbjerke_splunk could add this documentation for the targeting of components to a distributed Splunk environment.

Unarchiving the conf files in this app shows the following configs below. Right away I notice indexes.conf which usually means an index is being defined. For the most part, this means this config should reside on your indexers. It would be helpful to know if the props.conf and transforms.conf (and any other confs) also need to reside on both search head and indexers.

SplunkAppForWebAnalytics/default/savedsearches.conf
SplunkAppForWebAnalytics/default/ui-prefs.conf
SplunkAppForWebAnalytics/default/eventtypes.conf
SplunkAppForWebAnalytics/default/datamodels.conf
SplunkAppForWebAnalytics/default/inputs.conf
SplunkAppForWebAnalytics/default/app.conf
SplunkAppForWebAnalytics/default/indexes.conf
SplunkAppForWebAnalytics/default/transforms.conf
SplunkAppForWebAnalytics/default/collections.conf
SplunkAppForWebAnalytics/default/tags.conf
SplunkAppForWebAnalytics/default/macros.conf
SplunkAppForWebAnalytics/default/props.conf

lavanyaanne
Path Finder

You can install The Application on Indexer (or) Search head.Based on your Data Traffic you can choose any one.If you don't want to give more load to your Search head then indexer is good.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...