All Apps and Add-ons

How to install and configure the Splunk App for Dropbox for Business in an indexer and search head clustering environment?

briangmadden
Explorer

I have a multi-node indexer cluster with a 3 node search head cluster and two load balanced Heavy forwarders in my Splunk environment. The security team has requested that we install & get the Splunk App for Dropbox for Business working. Does anybody know what the actual steps are in getting the app working in such an environment? Ideally, the connection to Dropbox will be initiated by HFs and sent to Indexers.

0 Karma
1 Solution

briangmadden
Explorer

Finally got this working in my environment. The lack of documentation is very frustrating.

  1. Create Dropbox index on the Index Cluster

  2. Install Dropbox App on Heavy Forwarder

  3. Rename indexes.conf in default folder on HF

  4. Add outputs.conf pointing to my IndexCluster in local folder of Dropbox App on HF.

  5. Install Dropbox App on Search Head Cluster.

  6. Change the event-type "dfb_activity" to include "index=your index_name" sourcetype=dfb:activity instead of calling the macro. This is required to get the dashboard working within the application.

View solution in original post

briangmadden
Explorer

Finally got this working in my environment. The lack of documentation is very frustrating.

  1. Create Dropbox index on the Index Cluster

  2. Install Dropbox App on Heavy Forwarder

  3. Rename indexes.conf in default folder on HF

  4. Add outputs.conf pointing to my IndexCluster in local folder of Dropbox App on HF.

  5. Install Dropbox App on Search Head Cluster.

  6. Change the event-type "dfb_activity" to include "index=your index_name" sourcetype=dfb:activity instead of calling the macro. This is required to get the dashboard working within the application.

stephanefotso
Motivator

Hello! You must use the configuration bundle method. For more information read this first http://docs.splunk.com/Documentation/Splunk/6.3.3/Indexer/Managecommonconfigurations
ant then read this: http://docs.splunk.com/Documentation/Splunk/6.3.3/Indexer/Manageappdeployment

Thanks

SGF
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...