All Apps and Add-ons

In a distributed Splunk environment, should Trend Micro Deep Security app be installed on heavy forwarders and indexers, as well as search heads?

PhilipShaunTayl
New Member

TM Deep Security app has index-time transforms in transforms.conf.

0 Karma
1 Solution

Grumpalot
Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

View solution in original post

0 Karma

Grumpalot
Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...