Quantcast
Viewing all articles
Browse latest Browse all 47296

Is it best practice to migrate eventtypes to the Search app with or without the search head cluster deployer?

Is it best practice to copy the /search/local directory to the new search head cluster members and not use the deployer? I used a deployer to set up LDAP, but per documentation, it says not to do the same for the search application. Per Documentation: The types of updates that the deployer handles These are the specific types of updates that require the deployer: - New or upgraded apps. - Configuration files that you edit directly. - **All non-search-related updates**, even those that can be configured through the CLI or Splunk Web, such as updates to indexes.conf or inputs.conf. - Settings that need to be migrated from a search head pool or a standalone search head. These can be app or user settings.

Viewing all articles
Browse latest Browse all 47296

Trending Articles