All Apps and Add-ons

Palo Alto Networks Add-on Install Locations

KevinMurray
Explorer

If I have the add-on installed on my heavy forwarder and search heads, is there any need to install it on my indexers as well?????

Labels (1)
0 Karma

ivanreis
Builder

Hi @KevinMurray, in general we usually deploy the add-on on Heavy Forwarder with the inputs.conf setup and for Indexer and Search Head tier without inputs.conf setup. The add-on is being used to normalise data, using the props and transforms.conf, so it is really important to install them

In this particular case, the add-on has a document that highlight "Where to Install" and can be found here:
https://splunk.paloaltonetworks.com/installation.html

I am adding other document where you can have more information where to install Splunk add-ons

https://docs.splunk.com/Documentation/AddOns/released/Overview/Wheretoinstall

Usually the apps and add-ons from Splunk base does have a document with this type of information to assist with.

If this help, please upvote. 

0 Karma

KevinMurray
Explorer

I suspect the add-on is NOT needed on the indexers since I have the add-on with inputs.conf on the heavy forwarder, but, I am going to install it on the indexers anyway without the inputs.conf (obviously)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...