Deployment Architecture

Is it possible to use SH-Deployer to Push User (Local) App?

morethanyell
Builder

Basically what I wish to do is very simple, I want to clone 70+ alerts (entire savedsearches.conf). I maybe naive but my plan is to clone them all but not via UI. How can I copy the entire savedsearches.conf we have in ../etc/apps/<appname>/default/savedsearches.conf into our SH deployer and let it apply cluster bundel into the ../etc/users/<username>/<appname>/local/ of our 14 search heads?

0 Karma
1 Solution

tiagofbmm
Influencer

SH Deployer deploys to apps folder only. If you want to push savedsearches to belong privately to users, I'd recommend using Ansible or other automation tool, which would be pretty simple to create there.

View solution in original post

tiagofbmm
Influencer

SH Deployer deploys to apps folder only. If you want to push savedsearches to belong privately to users, I'd recommend using Ansible or other automation tool, which would be pretty simple to create there.

morethanyell
Builder

Hi @tiagofbmm please convert your comment to answer as it directly answers my question. I will accept it. By the way, thank you very much.

0 Karma

tiagofbmm
Influencer

You're welcome. It is converted now 😉

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...