Deployment Architecture

Splunk add-on for AWS installation

brandy81
Path Finder

Hi all,

I have a question for installing Splunk add for AWS / Splunk add-on for AWS.

My on-prem deployment is like this:

datasource <-> HF <-> IDX cluster <-> SH cluster

Where do I have to install app/add-on?

https://docs.splunk.com/Documentation/AWS/6.0.1/Installation/Installon-prem: It says both should be installed on SH and add-on should be on HF.

https://docs.splunk.com/Documentation/AddOns/released/AWS/Distributeddeployment: It's table says add-on should be only on HF.

Which document is correct? Thanks in advance.

 

Labels (1)
Tags (1)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

based on your Splunk deployment. Data collection should be always on Heavy forwarder. since the TA is used to collect data from AWS, you should install it on Heavy forwarder. But, most of the TAs will have search time field extractions, event types and tags. Hence it may be required to install on search heads as well.

————————————
If this helps, give a like below.

View solution in original post

0 Karma

vikramyadav
Contributor

You can install Splunk add-on for AWS on Heavy Forwarder to pull data from AWS.
https://splunkbase.splunk.com/app/1876/


And Splunk App for AWS on Search Head.
https://splunkbase.splunk.com/app/1274/

-----------------------------------------------------------
If this helps, your like will be appreciated. 😊

 

0 Karma

thambisetty
SplunkTrust
SplunkTrust

based on your Splunk deployment. Data collection should be always on Heavy forwarder. since the TA is used to collect data from AWS, you should install it on Heavy forwarder. But, most of the TAs will have search time field extractions, event types and tags. Hence it may be required to install on search heads as well.

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...