All Apps and Add-ons

Splunk Add-on for Windows Installation Questions

adamblock1
Explorer

Is it possible to install the Splunk Add-on for Windows solely on a search head, or must it also be installed on indexers as well? If this is possible, must the search head be running on a Windows platform?

Thank you.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

You should install it on indexers, search heads, and Windows hosts. The docs say install it everywhere. 🙂 See Download and configure the Splunk Add-on for Windows.

The system requirements in the documentation also say "You can install the app on a non-Windows Splunk Enterprise instance to display Windows data coming from external Windows sources."

0 Karma

adamblock1
Explorer

I am currently working with a test system, and currently only have access to the search head. If the add-on would be installed on the search head, and not on the indexer(s), does that mean that whatever parsing is performed will be performed at search time as opposed to when the events are indexed?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

If you have the Windows add-on only on a search head, then you get:

  • Windows data if the search head is a Windows host and you enable data collection
  • Search-time parsing and field extraction
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...