<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add-on installation on Search Head or on Indexer? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546267#M7301</link>
    <description>&lt;P class="lia-align-left"&gt;Thanks for your reply. I see a lot of posts though mentioning that installing addons (eg CIM) on indexers is not recommended as this might cause performance issue to an already stressed indexer. Eg. it might cause an additional attempt for datamodel acceleration.&lt;BR /&gt;&lt;BR /&gt;What is the best practice?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 31 Mar 2021 15:59:41 GMT</pubDate>
    <dc:creator>b_chris21</dc:creator>
    <dc:date>2021-03-31T15:59:41Z</dc:date>
    <item>
      <title>Add-on installation on Search Head or on Indexer?</title>
      <link>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546263#M7297</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;my distributed environment consists of:&lt;/P&gt;&lt;P&gt;1) Splunk Enterprise Security (Deployment Server/Search Head) - RHEL7.9&lt;BR /&gt;2) Splunk Indexer (Deployment Client) - RHEL7.9&lt;BR /&gt;3) WEF server (Windows Server 2016) which collects Windows Event Logs and sysmon events from systems that belong to the domain. There is a Splunk UF installed which forwards the events to Splunk Indexer (2).&lt;BR /&gt;&lt;BR /&gt;Question:&lt;BR /&gt;&lt;BR /&gt;I want to keep the data to indexer (2), but I want to be able to populate the respective datamodels in Splunk ES and get notable events for suspicious traffic in the domain.&lt;BR /&gt;&lt;BR /&gt;Where do I have to install the necessary addons that will normalize the data? On Splunk ES (1) or Splunk Indexer (2) ?&lt;BR /&gt;&lt;BR /&gt;Thank you in advance,&lt;BR /&gt;&lt;BR /&gt;Chris&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:49:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546263#M7297</guid>
      <dc:creator>b_chris21</dc:creator>
      <dc:date>2021-03-31T15:49:19Z</dc:date>
    </item>
    <item>
      <title>Re: Add-on installation on Search Head or on Indexer?</title>
      <link>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546264#M7298</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/41609"&gt;@b_chris21&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Configurations and updates needed for the data model to normalize the data are done on&lt;SPAN&gt;&amp;nbsp;search heads only.&lt;BR /&gt;You need to deploy the add-ons on search head - Splunk ES (1).&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this reply helps you, a like would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546264#M7298</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-03-31T15:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Add-on installation on Search Head or on Indexer?</title>
      <link>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546265#M7299</link>
      <description>&lt;P&gt;Most add-ons should be installed on BOTH the indexer and the search head.&amp;nbsp; That's because they often have some properties that apply at index time and others that apply at search time.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546265#M7299</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-31T15:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Add-on installation on Search Head or on Indexer?</title>
      <link>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546266#M7300</link>
      <description>&lt;P&gt;Thanks for your rapid reply.&lt;BR /&gt;&lt;BR /&gt;What is the best solution to bring indexed data in Splunk ES and populate lookups? I see Sec-Kit app is built to do that. Shall I install Sec-Kit in Splunk ES directly?&lt;BR /&gt;&lt;BR /&gt;Thanks again.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:57:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546266#M7300</guid>
      <dc:creator>b_chris21</dc:creator>
      <dc:date>2021-03-31T15:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Add-on installation on Search Head or on Indexer?</title>
      <link>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546267#M7301</link>
      <description>&lt;P class="lia-align-left"&gt;Thanks for your reply. I see a lot of posts though mentioning that installing addons (eg CIM) on indexers is not recommended as this might cause performance issue to an already stressed indexer. Eg. it might cause an additional attempt for datamodel acceleration.&lt;BR /&gt;&lt;BR /&gt;What is the best practice?&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546267#M7301</guid>
      <dc:creator>b_chris21</dc:creator>
      <dc:date>2021-03-31T15:59:41Z</dc:date>
    </item>
    <item>
      <title>Re: Add-on installation on Search Head or on Indexer?</title>
      <link>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546279#M7302</link>
      <description>&lt;P&gt;That depends on the add-on, which is why each should be examined (or at least read the docs) before it is installed.&lt;/P&gt;&lt;P&gt;Datamodel accelerations are initiated by search heads rather than indexers.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 17:30:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Add-on-installation-on-Search-Head-or-on-Indexer/m-p/546279#M7302</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-31T17:30:35Z</dc:date>
    </item>
  </channel>
</rss>

