All Apps and Add-ons

Splunk Add-on for Microsoft Windows: Which components should I deploy the add-on to?

shubham87
Explorer

We have a distributed Splunk environment. We are using a universal forwarder to get logs from a Windows server. Deployment server is being used to deploy apps to different components. To which components should I deploy the Splunk Add-on for Microsoft Windows?

0 Karma

woodcock
Esteemed Legend

It depends but the general answer is "probably everywhere except for linux forwarders". See here:

https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/DeploytheSplunkAdd-onforWindowsinadis...

0 Karma

adonio
Ultra Champion

hello there,

start here:
http://docs.splunk.com/Documentation/MSApp/1.4.1/MSInfra/WhataSplunkAppforWindowsInfrastructuredeplo...
and read thoroughly through the doc
it explains in detail where each component (TA / app / SA) should be
the TA for windows itself should be on all splunk components, Forwarder, indexer and Search Head.
also on the Deployment Server (in /etc/deployment-apps) if you use it to push to forwarders.
hope it helps

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...