All Apps and Add-ons

How to deploy the Splunk Add-on for Blue Coat ProxySG in an indexer clustering environment?

daniel_augustyn
Contributor

Where should I deploy the Blue Coat Add-on for proxy SG logs? I'm running a Splunk indexer cluster with a couple of indexers, a master, and a search head. I wanted to find out where to install the app for the field extractions. Should this be done on the indexers? What about the add-on for Blue Coat, should this be installed on the search head and available for end users? I'm kind of confused how this should be deployed. Right now, I am pushing proxy logs from the FTP server to both indexers.

0 Karma
1 Solution

rpille_splunk
Splunk Employee
Splunk Employee

You should install the add-on to your search heads, indexers, and forwarders. The data collection should be done on forwarders rather than on indexers as a best practice. If you happen to use heavy forwarders for your data collection, you do not need to install the add-on to indexers in that case.

Here is the add-on documentation's installation instructions: http://docs.splunk.com/Documentation/AddOns/latest/BlueCoatProxySG/Install

View solution in original post

rpille_splunk
Splunk Employee
Splunk Employee

You should install the add-on to your search heads, indexers, and forwarders. The data collection should be done on forwarders rather than on indexers as a best practice. If you happen to use heavy forwarders for your data collection, you do not need to install the add-on to indexers in that case.

Here is the add-on documentation's installation instructions: http://docs.splunk.com/Documentation/AddOns/latest/BlueCoatProxySG/Install

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...