<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tenable App for Splunk use with Heavy Forwarder in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746259#M81922</link>
    <description>&lt;P&gt;Depends on what you means by "require HF". Modular inputs must be run on a "full" Splunk Enterprise instance. So in this meaning - it requires HF because it won't run on UF. Technically you can run the modular input on an All-in-one instance without spinning up a separate HF. While you could run it also directly on an indexer or SH, it's not a recommended architecture - those roles are best left alone with what they do.&lt;/P&gt;</description>
    <pubDate>Thu, 15 May 2025 14:45:53 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2025-05-15T14:45:53Z</dc:date>
    <item>
      <title>Tenable App for Splunk use with Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746249#M81920</link>
      <description>&lt;P&gt;I am trying to set up the Tenable App for Splunk and the documentation is a bit vague about whether it requires a Heavy Forwarder to operate.&amp;nbsp; I found an old post from 2017 that mentioned it did, but it was referencing older versions of Nessus than what is used in my environment.&amp;nbsp; Does anyone know if a heavy forwarder is still required for the&amp;nbsp; Tenable App for Splunk?&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 13:27:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746249#M81920</guid>
      <dc:creator>gheller</dc:creator>
      <dc:date>2025-05-15T13:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable App for Splunk use with Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746251#M81921</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310201"&gt;@gheller&lt;/a&gt;&amp;nbsp;Inputs must be configured to run from the Heavy Forwarder.&amp;nbsp;&lt;SPAN&gt;The&amp;nbsp;&lt;/SPAN&gt;Search Head&lt;SPAN&gt;&amp;nbsp;is used for dashboards and adaptive response actions, but it relies on data collected and forwarded by the Heavy Forwarder.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;It's important to enable the KV Store on the Heavy Forwarder to support the add-on's functionality&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.tenable.com/integrations/Splunk/Content/PDF/Tenable_and_Splunk_Integration_Guide.pdf" target="_blank" rel="noopener"&gt;Tenable and Splunk Integration Guide&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The&amp;nbsp;&lt;SPAN class=""&gt;Tenable&lt;/SPAN&gt;&amp;nbsp;Add-on has specific purposes for each Splunk component.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.tenable.com/integrations/Splunk/Content/Components.htm" target="_blank" rel="noopener"&gt;Components&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1747317791074.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39019iF71532F44348B501/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1747317791074.png" alt="kiran_panchavat_0-1747317791074.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Install the add-on on both the Heavy Forwarder and the Search Head but create data inputs only on the heavy forwarder.&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4060" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4060&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Install the app exclusively on the Search Head.&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4061" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/4061&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 14:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746251#M81921</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-15T14:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable App for Splunk use with Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746259#M81922</link>
      <description>&lt;P&gt;Depends on what you means by "require HF". Modular inputs must be run on a "full" Splunk Enterprise instance. So in this meaning - it requires HF because it won't run on UF. Technically you can run the modular input on an All-in-one instance without spinning up a separate HF. While you could run it also directly on an indexer or SH, it's not a recommended architecture - those roles are best left alone with what they do.&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 14:45:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746259#M81922</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-05-15T14:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Tenable App for Splunk use with Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746263#M81923</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310201"&gt;@gheller&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;The latest docs are at&amp;nbsp;&lt;A href="https://docs.tenable.com/integrations/Splunk/Content/Welcome.htm" target="_blank" rel="noopener"&gt;https://docs.tenable.com/integrations/Splunk/Content/Welcome.htm&lt;/A&gt;&amp;nbsp;which they have recently updated, there is a great diagram to show where things should be installed:&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="livehybrid_0-1747321214213.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39021i88886EBFC24934F9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="livehybrid_0-1747321214213.png" alt="livehybrid_0-1747321214213.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&amp;nbsp;&lt;DIV class=""&gt;&amp;nbsp;&lt;P&gt;&lt;IMG border="0" /&gt;&lt;/P&gt;&lt;P&gt;In short, the&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4060" target="_self"&gt;Tenable Add-On for Splunk&lt;/A&gt;&amp;nbsp;should be installed on your SH and HF (with inputs created on HF, or pushed out via your deployment server to HF if appropriate) and then install the&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/4061" target="_self"&gt;Tenable App for Splunk&amp;nbsp;on just the SH).&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;STRONG&gt;Did this answer help you?&lt;SPAN&gt;&amp;nbsp;If so, please consider:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 May 2025 15:00:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Tenable-App-for-Splunk-use-with-Heavy-Forwarder/m-p/746263#M81923</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-15T15:00:53Z</dc:date>
    </item>
  </channel>
</rss>

