<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where shoulld I install Azure Monitor Add-on For Splunk? (Heavy forwarder/indexer/Search head)? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453601#M55775</link>
    <description>&lt;P&gt;thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;BR /&gt;
can you please explain why it's Ideally  to install it on the HF ? and why to avoid installing it on the Indexer? and what do you mean by "unless its all in one"?&lt;/P&gt;

&lt;P&gt;thank you&lt;/P&gt;</description>
    <pubDate>Sun, 22 Jul 2018 20:09:44 GMT</pubDate>
    <dc:creator>Koko12345678</dc:creator>
    <dc:date>2018-07-22T20:09:44Z</dc:date>
    <item>
      <title>Where shoulld I install Azure Monitor Add-on For Splunk? (Heavy forwarder/indexer/Search head)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453595#M55769</link>
      <description>&lt;P&gt;HI ,&lt;/P&gt;

&lt;P&gt;I would like to know where should I install the Azure Monitor Add-on For Splunk?  on which of this component? Heavy forwarder, indexer , Search head? &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 15:36:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453595#M55769</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-07-22T15:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Where shoulld I install Azure Monitor Add-on For Splunk? (Heavy forwarder/indexer/Search head)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453596#M55770</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Better to install on HF.&lt;/P&gt;

&lt;P&gt;Because INDEXER IS BUSY IN indexing data.&lt;BR /&gt;
Search head is busy in searching.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 15:46:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453596#M55770</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2018-07-22T15:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Where shoulld I install Azure Monitor Add-on For Splunk? (Heavy forwarder/indexer/Search head)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453597#M55771</link>
      <description>&lt;P&gt;as far as I know HF is busy in parsing the data,then I'm just asking myself why HF is the better place? &lt;BR /&gt;
in addition, where Should I configure the Inputs( input for Activity Logs/Diagnostics Logs) in splunk? is it in the search head?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 15:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453597#M55771</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-07-22T15:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: Where shoulld I install Azure Monitor Add-on For Splunk? (Heavy forwarder/indexer/Search head)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453598#M55772</link>
      <description>&lt;P&gt;Its fully dependent on your environment.&lt;/P&gt;

&lt;P&gt;In my case we have search heads loaded with so many scheduled searches so I could not allocate even 1 cpu for modular/scripted inputs and we have Indexers are busy in responding to searches and indexing data. Thats y I recommend to have modular inputs on HF.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 17:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453598#M55772</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2018-07-22T17:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Where shoulld I install Azure Monitor Add-on For Splunk? (Heavy forwarder/indexer/Search head)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453599#M55773</link>
      <description>&lt;P&gt;ok thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 17:38:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453599#M55773</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-07-22T17:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Where shoulld I install Azure Monitor Add-on For Splunk? (Heavy forwarder/indexer/Search head)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453600#M55774</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;

&lt;P&gt;ideally on the Heavy Forwarder, if not in the Search Head. &lt;BR /&gt;
Avoid installing on indexer (unless its all in one)&lt;/P&gt;

&lt;P&gt;hope it helps&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 18:14:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453600#M55774</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-07-22T18:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Where shoulld I install Azure Monitor Add-on For Splunk? (Heavy forwarder/indexer/Search head)?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453601#M55775</link>
      <description>&lt;P&gt;thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;BR /&gt;
can you please explain why it's Ideally  to install it on the HF ? and why to avoid installing it on the Indexer? and what do you mean by "unless its all in one"?&lt;/P&gt;

&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Sun, 22 Jul 2018 20:09:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Where-shoulld-I-install-Azure-Monitor-Add-on-For-Splunk-Heavy/m-p/453601#M55775</guid>
      <dc:creator>Koko12345678</dc:creator>
      <dc:date>2018-07-22T20:09:44Z</dc:date>
    </item>
  </channel>
</rss>

