All Apps and Add-ons

In a distributed Splunk environment, should Trend Micro Deep Security app be installed on heavy forwarders and indexers, as well as search heads?

PhilipShaunTayl
New Member

TM Deep Security app has index-time transforms in transforms.conf.

0 Karma
1 Solution

Grumpalot
Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

View solution in original post

0 Karma

Grumpalot
Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...