<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you install the Symantec Security Analytics App in a distributed deployment with a SHC? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-you-install-the-Symantec-Security-Analytics-App-in-a/m-p/395361#M48253</link>
    <description>&lt;P&gt;I've been asked to deploy the Symantec Security Analytics (SA) App For Splunk in an environment that consists of a SHC and a clustered indexing tier.&lt;/P&gt;

&lt;P&gt;The SA admin has provided me with a couple of TGZ files (SymantecSecurityAnalytics7.2-11.tgz and TA-symantec-sa-11.tgz) and with a 3 page PDF that claims to be an "Install Guide".  The PDF provides a rudimentary set of instructions, but itr's clearly geared towards a installation on a single-instance Splunk deployment.   I also found this &lt;A href="https://www.symantec.com/connect/sites/default/files/Symantec%20Security%20Analytics%20App%20For%20Splunk_V2.pdf"&gt;PDF&lt;/A&gt; on Symtantec's site but it too is geared towards to single-instance deployment.&lt;/P&gt;

&lt;P&gt;Has anyone successfuly installed and configured the App (and TA) in a distributed environment with a SHC and, if so, how?&lt;/P&gt;

&lt;P&gt;On a related note, the PDF says to modify the two Workflow Actions by replacing the default IP address (127.0.0.1) in the URI with the IP address of "&lt;STRONG&gt;the&lt;/STRONG&gt; sensor" (emphasis added by me) - but the SA admin says that there are multiple SA sensors so it's not clear what to do.  Apparently the sensors sense different things so we can't (we believe) query just one sensor.   The SA admin has suggested using the address of the "Central Management Console" (CMC) - does anyone know if this will work?&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jun 2018 22:23:00 GMT</pubDate>
    <dc:creator>chris_barrett</dc:creator>
    <dc:date>2018-06-18T22:23:00Z</dc:date>
    <item>
      <title>How do you install the Symantec Security Analytics App in a distributed deployment with a SHC?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-you-install-the-Symantec-Security-Analytics-App-in-a/m-p/395361#M48253</link>
      <description>&lt;P&gt;I've been asked to deploy the Symantec Security Analytics (SA) App For Splunk in an environment that consists of a SHC and a clustered indexing tier.&lt;/P&gt;

&lt;P&gt;The SA admin has provided me with a couple of TGZ files (SymantecSecurityAnalytics7.2-11.tgz and TA-symantec-sa-11.tgz) and with a 3 page PDF that claims to be an "Install Guide".  The PDF provides a rudimentary set of instructions, but itr's clearly geared towards a installation on a single-instance Splunk deployment.   I also found this &lt;A href="https://www.symantec.com/connect/sites/default/files/Symantec%20Security%20Analytics%20App%20For%20Splunk_V2.pdf"&gt;PDF&lt;/A&gt; on Symtantec's site but it too is geared towards to single-instance deployment.&lt;/P&gt;

&lt;P&gt;Has anyone successfuly installed and configured the App (and TA) in a distributed environment with a SHC and, if so, how?&lt;/P&gt;

&lt;P&gt;On a related note, the PDF says to modify the two Workflow Actions by replacing the default IP address (127.0.0.1) in the URI with the IP address of "&lt;STRONG&gt;the&lt;/STRONG&gt; sensor" (emphasis added by me) - but the SA admin says that there are multiple SA sensors so it's not clear what to do.  Apparently the sensors sense different things so we can't (we believe) query just one sensor.   The SA admin has suggested using the address of the "Central Management Console" (CMC) - does anyone know if this will work?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 22:23:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-you-install-the-Symantec-Security-Analytics-App-in-a/m-p/395361#M48253</guid>
      <dc:creator>chris_barrett</dc:creator>
      <dc:date>2018-06-18T22:23:00Z</dc:date>
    </item>
  </channel>
</rss>

