All Apps and Add-ons
Highlighted

Installation Question - Windows Defender ATP Modular Inputs TA

Path Finder

On the Splunk side , in a Distributed environment, where should this Windows Defender ATP Modular Inputs TA be installed ?
Only on the Search Heads ?

0 Karma
Highlighted

Re: Installation Question - Windows Defender ATP Modular Inputs TA

Builder

Hi @rajanala ,

It looks like it should be installed on:
A heavy forwarder & search head(s)

It's recommended to put it on a heavy forwarder, where the data will be collected by the modular inputs, and then sent to the indexers. The search heads will need to get a copy for any search-time configurations.

0 Karma