All Apps and Add-ons

Splunk Add-on for Microsoft Windows: Which components should I deploy the add-on to?

shubham87
Explorer

We have a distributed Splunk environment. We are using a universal forwarder to get logs from a Windows server. Deployment server is being used to deploy apps to different components. To which components should I deploy the Splunk Add-on for Microsoft Windows?

0 Karma

woodcock
Esteemed Legend

It depends but the general answer is "probably everywhere except for linux forwarders". See here:

https://docs.splunk.com/Documentation/WindowsAddOn/latest/User/DeploytheSplunkAdd-onforWindowsinadis...

0 Karma

adonio
Ultra Champion

hello there,

start here:
http://docs.splunk.com/Documentation/MSApp/1.4.1/MSInfra/WhataSplunkAppforWindowsInfrastructuredeplo...
and read thoroughly through the doc
it explains in detail where each component (TA / app / SA) should be
the TA for windows itself should be on all splunk components, Forwarder, indexer and Search Head.
also on the Deployment Server (in /etc/deployment-apps) if you use it to push to forwarders.
hope it helps

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...