<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What do I need to do to run Anti Virus software with Splunk on Windows? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-do-to-run-Anti-Virus-software-with-Splunk-on/m-p/77386#M15854</link>
    <description>&lt;P&gt;Correct  - &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/ReleaseNotes/RunningSplunkalongsideWindowsantivirusproducts"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/ReleaseNotes/RunningSplunkalongsideWindowsantivirusproducts&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 14 Jan 2019 21:22:23 GMT</pubDate>
    <dc:creator>jaxjohnny2000</dc:creator>
    <dc:date>2019-01-14T21:22:23Z</dc:date>
    <item>
      <title>What do I need to do to run Anti Virus software with Splunk on Windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-do-to-run-Anti-Virus-software-with-Splunk-on/m-p/77384#M15852</link>
      <description>&lt;P&gt;I am running Splunk and want to run Anti Virus with it.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2010 01:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-do-to-run-Anti-Virus-software-with-Splunk-on/m-p/77384#M15852</guid>
      <dc:creator>Simeon</dc:creator>
      <dc:date>2010-10-26T01:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: What do I need to do to run Anti Virus software with Splunk on Windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-do-to-run-Anti-Virus-software-with-Splunk-on/m-p/77385#M15853</link>
      <description>&lt;P&gt;Because Splunk index and search does a lot of IO/CPU/Memory/Network, most anti-virus software will suspect that Splunk is malware on indexers and search heads.&lt;/P&gt;

&lt;P&gt;The mainstream solution to this problem is also the simplest one, namely to exclude directories and processes of applications that perform heavy lifting from virus scans:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="http://support.microsoft.com/kb/309422" target="test_blank"&gt;http://support.microsoft.com/kb/309422&lt;/A&gt;
&lt;A href="http://support.microsoft.com/kb/822158" target="test_blank"&gt;http://support.microsoft.com/kb/822158&lt;/A&gt;
&lt;A href="http://technet.microsoft.com/en-us/library/bb332342.aspx" target="test_blank"&gt;http://technet.microsoft.com/en-us/library/bb332342.aspx&lt;/A&gt;
&lt;A href="http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2002092413394848" target="test_blank"&gt;http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2002092413394848&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My recommendation is that the directory “$SPLUNK_HOME/var” (as well as any alternate $SPLUNK_DB locations) and the processes splunkd.exe, splunk-search.exe and splunk-optimize.exe should be excluded from file and real-time scanning on any servers that do indexing and search.&lt;/P&gt;

&lt;P&gt;I do not think that forwarders present a problem given that there is little to no indexing performed locally, and I haven’t heard of many customers who are primarily using Splunk as a forwarder rather than an indexer on Windows platforms bringing A/V problems to support.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2010 01:28:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-do-to-run-Anti-Virus-software-with-Splunk-on/m-p/77385#M15853</guid>
      <dc:creator>araitz</dc:creator>
      <dc:date>2010-10-26T01:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: What do I need to do to run Anti Virus software with Splunk on Windows?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-do-to-run-Anti-Virus-software-with-Splunk-on/m-p/77386#M15854</link>
      <description>&lt;P&gt;Correct  - &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/ReleaseNotes/RunningSplunkalongsideWindowsantivirusproducts"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/ReleaseNotes/RunningSplunkalongsideWindowsantivirusproducts&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2019 21:22:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-do-I-need-to-do-to-run-Anti-Virus-software-with-Splunk-on/m-p/77386#M15854</guid>
      <dc:creator>jaxjohnny2000</dc:creator>
      <dc:date>2019-01-14T21:22:23Z</dc:date>
    </item>
  </channel>
</rss>

