All Apps and Add-ons

In a distributed Splunk environment, should Trend Micro Deep Security app be installed on heavy forwarders and indexers, as well as search heads?

PhilipShaunTayl
New Member

TM Deep Security app has index-time transforms in transforms.conf.

0 Karma
1 Solution

Grumpalot
Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

View solution in original post

0 Karma

Grumpalot
Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...