Getting Data In

If I need an Add-On like for VMware ESXI Logs, do I install that on the UF or request installation in Splunk Cloud?

skeer007
Explorer

I have a Universal Forwarder accepting syslog traffic from multiple sources.  The UF forwards up to indexers in Splunk Cloud.
My question is two-fold:   If I need an Add-On like for VMware ESXI Logs. Do I install that on the UF or request installation in Splunk Cloud?

And if the latter, how does my UF know that I can now use any new sourcetypes?  I've read through the installation notes on a few Add-Ons and have not seen mention of how new sourcetypes are used outside of the server or instance the add-on is directly isntalled.

 

Thanks!

Labels (2)
0 Karma

skeer007
Explorer

Ok that all makes sense, So knowing what sourcetypes are available from an add-on depends on how well it's documented I guess? 

Hmm, so your comment about UF rarely using add-ons.. I guess that's why I haven't really seen "Forwarders" mentioned often in the details for add-ons. Are TA's usually different? Looking at this one: https://splunkbase.splunk.com/app/3662/ and it specifically mentions forwarders.  

Did I make this harder than it really is?  🙂

0 Karma

richgalloway
SplunkTrust
SplunkTrust

A well-documented add-on will list the sourcetypes it makes available.  For others, download it and look in the default/props.conf file.

TA and add-on are different terms for the same thing.  TA is short for "technical add-on".

Some add-on do have to be installed on forwarders.  The instructions should say when that's the case, but when an add-on uses a third-party API then it probably should be installed on a forwarder.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Usually, there's no harm in installing an add-on on a UF, although the UF rarely uses them.  They're more likely to be needed on indexers and search heads, however.  The installation instructions for the add-on should specify where it should be installed.

The UF doesn't know if any particular add-on is installed on the indexers or not.  Don't enable an input that needs an add-on until that add-on is ready.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...