All Apps and Add-ons
Highlighted

In a distributed Splunk environment, should Trend Micro Deep Security app be installed on heavy forwarders and indexers, as well as search heads?

New Member

TM Deep Security app has index-time transforms in transforms.conf.

0 Karma

Re: In a distributed Splunk environment, should Trend Micro Deep Security app be installed on heavy forwarders and indexers, as well as search heads?

Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

View solution in original post

0 Karma