Getting Data In

Integration of Jamf-pro with splunk

veeeeruuuu
Loves-to-Learn

Please guide me on integrating jamf-pro with splunk step by step.

Jamf Pro Add-on for Splunk | Splunkbase

This is the add-on I need to install.

jamf-add-on.PNG

Please guide me on which instance (HF, Syslog servers, Search Heads, Indexers, Cluster master, License manager, Deployment server) should I install this add-on? 

And custom index, should it be created on cluster master and push the bundle to all indexers?

should I create on all 3 search heads and 1 adhoc search head that we have?

And please guide how the HF forwards the required events to this newly created index? how to let HF know that there is a custom index?

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...