Getting Data In

If I need an Add-On like for VMware ESXI Logs, do I install that on the UF or request installation in Splunk Cloud?

skeer007
Explorer

I have a Universal Forwarder accepting syslog traffic from multiple sources.  The UF forwards up to indexers in Splunk Cloud.
My question is two-fold:   If I need an Add-On like for VMware ESXI Logs. Do I install that on the UF or request installation in Splunk Cloud?

And if the latter, how does my UF know that I can now use any new sourcetypes?  I've read through the installation notes on a few Add-Ons and have not seen mention of how new sourcetypes are used outside of the server or instance the add-on is directly isntalled.

 

Thanks!

Labels (2)
0 Karma

skeer007
Explorer

Ok that all makes sense, So knowing what sourcetypes are available from an add-on depends on how well it's documented I guess? 

Hmm, so your comment about UF rarely using add-ons.. I guess that's why I haven't really seen "Forwarders" mentioned often in the details for add-ons. Are TA's usually different? Looking at this one: https://splunkbase.splunk.com/app/3662/ and it specifically mentions forwarders.  

Did I make this harder than it really is?  🙂

0 Karma

richgalloway
SplunkTrust
SplunkTrust

A well-documented add-on will list the sourcetypes it makes available.  For others, download it and look in the default/props.conf file.

TA and add-on are different terms for the same thing.  TA is short for "technical add-on".

Some add-on do have to be installed on forwarders.  The instructions should say when that's the case, but when an add-on uses a third-party API then it probably should be installed on a forwarder.

---
If this reply helps you, Karma would be appreciated.
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Usually, there's no harm in installing an add-on on a UF, although the UF rarely uses them.  They're more likely to be needed on indexers and search heads, however.  The installation instructions for the add-on should specify where it should be installed.

The UF doesn't know if any particular add-on is installed on the indexers or not.  Don't enable an input that needs an add-on until that add-on is ready.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...