Where do you install this?

New Member

Hi Guys,

This is most likely a silly question but I can get this add on to work. I have a Splunk cluster and my understanding is this add-on gets pushed out to the Universal Forwarders and the send in the converted log.

I get the log but its just a straight string, No formating, nothing.

Can anyone explain where this should be installed?

New Member

Thanks, Anmol Patel

I will get back to you soon if that works. Appreciate the help

@bobinnz refer to this doc, it lists out thee context on how and where to deploy the add-on based on the content.

