All Apps and Add-ons

Does Rubrik add-on work with clustered search heads, heavyweight forwarders and deployment servers

rickybails
Loves-to-Learn Lots

Does this add-on work in a clustered environment, with clustered indexers, search heads, with the data being collected by heavyweight forwarders that are updated via a deployment server?

Tags (1)
0 Karma

adonio
Ultra Champion

Hello there,

the add-on is intended to be installed on a full Splunk instance, hence a Heavy Forwarder as teh input is via REST API (modular input)
read ore here:
https://docs.splunk.com/Documentation/Splunk/7.2.3/AdvancedDev/ModInputsIntro

i will recommend the Heavy Forwarder to be independent for these kind of inputs, meaning, not deploy those inputs via Deployment Server. if you wish, you can deploy other configurations to the Heavy Forwarder, example will be: outputs.conf

here is a link for the app and in particular to the install instructions:
https://github.com/rubrikinc/rubrik-addon-for-splunk/blob/master/docs/quick-start.md

hope it helps

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...