<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder Technology Add-On in Security</title>
    <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669677#M17430</link>
    <description>&lt;P&gt;can u share the TA UF, specifically used for ES?&lt;BR /&gt;Or the download link or any helpful screenshot&lt;/P&gt;</description>
    <pubDate>Fri, 24 Nov 2023 18:06:55 GMT</pubDate>
    <dc:creator>Mohamad_Alaa</dc:creator>
    <dc:date>2023-11-24T18:06:55Z</dc:date>
    <item>
      <title>Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669354#M17402</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;I installed enterprise security on the search head and downloaded Splunk_TA_ForIndexer from ES General settings&lt;BR /&gt;&lt;BR /&gt;now i am stuck for UF technology add-on, from where i can find it? no option from the ES interface and i can't find it on splunkbase portal&lt;BR /&gt;I tried multiple search keyword on splunkbase with no luck&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 15:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669354#M17402</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-21T15:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669359#M17403</link>
      <description>&lt;P&gt;Why are you looking for that TA?&amp;nbsp; What problem are you trying to solve?&amp;nbsp; What documentation said to install the UF TA?&lt;/P&gt;&lt;P&gt;If you are a Splunk Cloud customer, the UF TA is available from your Splunk Cloud search head.&amp;nbsp; Open the "Universal Forwarder" app then click the green Download button.&amp;nbsp; If you are not a Splunk Cloud customer then you probably don't need the TA, depending on the answers to the above questions.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 15:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669359#M17403</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-11-21T15:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669429#M17407</link>
      <description>&lt;P&gt;i am using splunk fully on prem - no cloud option&lt;/P&gt;&lt;P&gt;as per documentation TA to be installed on UF, you can refer to below link&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669359#M17403" target="_blank"&gt;https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669359#M17403&lt;/A&gt;&lt;/P&gt;&lt;P&gt;As i understood, TA to be installed on Indexers (already done) and on UF&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 08:33:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669429#M17407</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-22T08:33:34Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669480#M17409</link>
      <description>&lt;P&gt;The link provided is to this question, not to any documentation.&lt;/P&gt;&lt;P&gt;If the TA is already installed on the indexers then you have what you need.&amp;nbsp; Just install the same TA on the forwarders.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 13:55:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669480#M17409</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-11-22T13:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669582#M17422</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the correct link&lt;/P&gt;&lt;P&gt;no one mentioned that it is the same TA for both, did you tried this before?&lt;BR /&gt;As per documentation it should be downloaded directly from splunkbase, but can't find it. The only thing i found is "Splunk-add-on-for-windows" but not sure if that's it or not&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 16:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669582#M17422</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-23T16:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669593#M17423</link>
      <description>&lt;P&gt;It's a general method of installing addons. You need addons for your particular sources.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 20:02:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669593#M17423</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-23T20:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669597#M17424</link>
      <description>&lt;P&gt;There's a lot of Splunk documentation so I understand why you don't have all the information yet.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Overview/Wheretoinstall" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Overview/Wheretoinstall&lt;/A&gt; for tips on where to install TAs.&amp;nbsp; The instructions that come with the TA are the best guide, however.&lt;/P&gt;&lt;P&gt;Splunkbase apps should be obtained directly from Splunkbase rather than via 3rd-party sources that may not be reputable.&amp;nbsp; However, once you've downloaded the TA it does not need to be downloaded again until a new version is available.&amp;nbsp; The one downloaded copy may be installed as many times as you wish.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 21:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669597#M17424</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-11-23T21:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669599#M17425</link>
      <description>&lt;P&gt;I appreciate all your efforts,&lt;BR /&gt;Now to make things clear,&lt;BR /&gt;1- Does i need to install TA Add-on on UF regarding ES? (yes or no) noting that all my values on the security posture dashboard still zero although i enabled all correlation searches&lt;BR /&gt;2- If yes i need on UF, from where i can download it? noting that i didn't find any TA on splunkbase&lt;BR /&gt;&lt;BR /&gt;thanks once again&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 21:46:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669599#M17425</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-23T21:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669603#M17426</link>
      <description>&lt;P&gt;First, do NOT enable all ES correlation searches.&amp;nbsp; That will cause more problems than it will solve.&amp;nbsp; Enable only the correlation searches that pertain to your use cases and for which you have data ingested in Splunk.&lt;/P&gt;&lt;P&gt;Where a TA should be installed depends on what the TA does.&amp;nbsp; The installation instructions for the TA should specify the location.&amp;nbsp; If it doesn't use the "Where to install" I link I provided earlier.&amp;nbsp; Generally speaking, it can't hurt to install a TA on both indexers and UFs.&lt;/P&gt;&lt;P&gt;Splunkbase is the source for most Splunk TAs.&amp;nbsp; Others can be downloaded from the vendors that created them for their products.&amp;nbsp; Still others are available from GitHub.&amp;nbsp; It can be difficult to locate a TA without knowing the name, however.&amp;nbsp; What do you want the TA to do?&amp;nbsp; Perhaps we can help you find something appropriate.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 00:58:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669603#M17426</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-11-24T00:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669677#M17430</link>
      <description>&lt;P&gt;can u share the TA UF, specifically used for ES?&lt;BR /&gt;Or the download link or any helpful screenshot&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 18:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669677#M17430</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-24T18:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669678#M17431</link>
      <description>&lt;P&gt;Again - there is no such thing as "add on for UF". There are several different add-ons (which you install on various components of your Splunk Infrastructure, including UFs) needed for specific solution you want to ingest data from.&lt;/P&gt;&lt;P&gt;So if you want to process logs from Checkpoint firewalls, you use TA for Checkpoint. If you get logs from Proofpoint you install UF for Proofpoint. And so on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 18:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669678#M17431</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-24T18:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669679#M17432</link>
      <description>&lt;P&gt;There is no UF add-on specific to ES.&amp;nbsp; ES can produce an add-on for your indexers, but that method can be used only in limited circumstances.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/ES/7.2.0/Install/InstallTechnologyAdd-ons#Deploy_add-ons_to_forwarders" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/7.2.0/Install/InstallTechnologyAdd-ons#Deploy_add-ons_to_forwarders&lt;/A&gt; for when it can be used and alternatives for other environments.&amp;nbsp; I recommend manual installation of add-ons.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 18:19:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669679#M17432</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-11-24T18:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669699#M17436</link>
      <description>&lt;P&gt;So if i have 50 devices i need to install the TA on all 50? lets assume cisco, fortinet, palo alto ...&lt;BR /&gt;So its not enough installing TA on idexers and already such devices are sending the logs to the indexer?&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2023 09:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669699#M17436</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-25T09:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669700#M17437</link>
      <description>&lt;P&gt;TA_for_indexers contains only the installation part needed for indexers (definition of indexes) that are needed for ES to work. But it's just so that ES on its own is "fully installed".&lt;/P&gt;&lt;P&gt;Apart from that Splunk (and ES too) needs to know how to work with specific types of data provided by various kinds of sources. That's what TAs for those sources are for.&lt;/P&gt;&lt;P&gt;So yes, if you have 40 _types_ of devices, you might need 40 different TAs. Often TAs contain definitions, parsing rules and CIM-mappings for multiple sources from a single vendor (so you might not need to have a separate TA for every single type of Juniper firewalls, just a single TA able to parse JunOS events).&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2023 09:37:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669700#M17437</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-25T09:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669726#M17439</link>
      <description>&lt;P&gt;ok much clear,&lt;/P&gt;&lt;P&gt;i have cisco switches, tried to search for that Add-on but with no luck. I can see cisco ESA, WSA, ISE ... but not IOS as switches or routers?&lt;/P&gt;&lt;P&gt;Moreover, installation tab is empty they are not includes the installation steps&lt;/P&gt;&lt;P&gt;any advise here?&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2023 07:48:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669726#M17439</guid>
      <dc:creator>Mohamad_Alaa</dc:creator>
      <dc:date>2023-11-26T07:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Technology Add-On</title>
      <link>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669761#M17441</link>
      <description>&lt;P&gt;Might be that those particular kinds of sources are not covered by any ready-made addons.&lt;/P&gt;&lt;P&gt;Splunk-supported Add-ons usually have their documentation on &lt;A href="https://docs.splunk.com/" target="_blank"&gt;https://docs.splunk.com/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Third-party addons - well, here you're on your own and on mercy of the addon creator.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2023 19:15:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Universal-Forwarder-Technology-Add-On/m-p/669761#M17441</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-26T19:15:35Z</dc:date>
    </item>
  </channel>
</rss>

