All Apps and Add-ons

Can you install Checkpoint addon on several heavy forwarders?

splunkreal
Motivator

Hello,

is it possible to install Checkpoint OPSEC LEA app on several heavy forwarders without duplicates, which architecture do you advice?

Thanks.

* If this helps, please upvote or accept solution if it solved *
0 Karma

tkopchak
SplunkTrust
SplunkTrust

No, multiple heavy forwarders connecting to the same management server would result in duplicated events. If you have multiple management servers, you could distribute that across multiple heavy forwarders, but you'd only want to collect each type of data from each management server once.

Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...