All Apps and Add-ons

Distributed splunk and Fireeye_v3

jgoddard
Path Finder

I am a bit unclear as to how to get this app configured correctly in a distributed setup.

I hope to use the REST api and JSON for the format of the data, and my plan was to point the Fireeye to the REST api of a heavy forwarder, but the documentation is not very clear as to whether this is possible, and whether this setup requires the full app to be on my heavy forwarder (as it appears from looking at the app).

Also, is the Fireeye_v3 app compatible with search head clusters?

Thanks,
Jim

0 Karma

TonyLeeVT
Builder

Sorry Jim. This is not a FireEye App specific question. This is more of a Splunk question of what is possible with a HF and what is required of a HF to work with apps (any app). We only supply the app and the TA.

There are distributed environments running the app and I can say that typically the app is installed on the search head and the TA's are installed on the HF and other components that do not need the UI. Please reach out to Splunk support with this question. If you send us the answer, we are more than happy to put it in the documentation for future reference and other users.

If you don't get anywhere with Splunk Support, shoot me an email through the app and maybe we can both get on the phone with them.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...