All Apps and Add-ons

Where should I install the Splunk Add-on for Microsoft Cloud Services?

Koko12345678
Explorer

I'm going to use Splunk on-prem with Azure, by installing Universal Forwarder on the VMs, but still going to use the Add-on for getting Azure audit logs.
Where should I install the add-on?
In addition, do I have to use Heavy forwarder (between the UF and the indexer) in this case?

Thanks

1 Solution

CarsonZa
Contributor

install the TA on the search head(s). its not necessary to send to a heavy forwarder but if you dont, you'll need to install on the indexers as well.

http://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/Install

View solution in original post

0 Karma

Koko12345678
Explorer

Thank you ! so I need to install The add-on only on the search head? or also on the heavy forwarder?

0 Karma

CarsonZa
Contributor

if you are sending any data to the hf from the ufs then yes install on the heavy forwarder and then you wont have to install on the indexers.

0 Karma

CarsonZa
Contributor

install the TA on the search head(s). its not necessary to send to a heavy forwarder but if you dont, you'll need to install on the indexers as well.

http://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/Install

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...