Getting Data In

How to configure inputs without duplicate data with an add on installed on HF/indexer, and SH?

lmjoin
Explorer

Hello Team,

I have one question . we have to installed addon on heavy forwarded or indexer and then need to install on search head. we are configuring addon on HV/I and SH . Could you please suggest both are configured for data inputs and not make duplicate data.

Thnk

0 Karma

vinkumar_splunk
Splunk Employee
Splunk Employee

I assume you have the add-on installed on HF / Indexer and SH and you want to know where to configure the inputs and ensure not to make duplicate data by configuring on multiple instances.

If the above is the case, then below is the answer to it. If not, please provide more information on your requirement.

Add-ons that contain inputs belong on forwarders, and in some select cases also on search heads. Inputs that contain dynamic lookups need to be installed on search heads because they feed results back into the input directly from the search. Consult the documentation of the add-on for special instructions.

https://docs.splunk.com/Documentation/AddOns/released/Overview/Wheretoinstall

0 Karma

woodcock
Esteemed Legend

Please have somebody else review what you are trying to say and expand your question for more clarity. I have no idea what you mean here.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...