Professional Documents
Culture Documents
1) Application APPS: This will be installed on Search Head. All searches, queries, dashboard,
report, alerts are stored in this APP.
2) Application TA or Add-on for Indexer: This will be installed on indexer. This helps in creating
necessary index for storing data for APP
3) Application TA or Add-on for Client ( Universal forwarder) : This will be installed on Client on
Universal forwarder. This helps in collecting necessary data from Client to Indexer
Login to Master Server ( in Distributed environment) > Click on Splunk * > Create APP specify App
name, App folder name.
homePath = $SPLUNK_DB/syslog/db
coldPath = $SPLUNK_DB/syslog/colddb
thawedPath = $SPLUNK_DB/syslog/thaweddb
maxDataSize = 10000
Prepare and deploy TA or Add-on on client using Deployment server ( part of Master)
Click on Apps: