All Apps and Add-ons

How do you install the Symantec Security Analytics App in a distributed deployment with a SHC?

chris_barrett
SplunkTrust
SplunkTrust

I've been asked to deploy the Symantec Security Analytics (SA) App For Splunk in an environment that consists of a SHC and a clustered indexing tier.

The SA admin has provided me with a couple of TGZ files (SymantecSecurityAnalytics7.2-11.tgz and TA-symantec-sa-11.tgz) and with a 3 page PDF that claims to be an "Install Guide". The PDF provides a rudimentary set of instructions, but itr's clearly geared towards a installation on a single-instance Splunk deployment. I also found this PDF on Symtantec's site but it too is geared towards to single-instance deployment.

Has anyone successfuly installed and configured the App (and TA) in a distributed environment with a SHC and, if so, how?

On a related note, the PDF says to modify the two Workflow Actions by replacing the default IP address (127.0.0.1) in the URI with the IP address of "the sensor" (emphasis added by me) - but the SA admin says that there are multiple SA sensors so it's not clear what to do. Apparently the sensors sense different things so we can't (we believe) query just one sensor. The SA admin has suggested using the address of the "Central Management Console" (CMC) - does anyone know if this will work?

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...