Hi All,
Duo connector installation docs for splunk isn't clear for multi site cluster environment. Can anyone suggest where to install this Duo connector app ?
I assume this needs to be installed on any HF and configure it to one custom index to receive the logs? I do have the admin api keys and other integration keys to configure it.
Please suggest if anyone installed Duo connector in multi site.
Hello @VK18,
Please install the app on a single Heavy Forwarder if you have one. If not, you can install the app on any one indexer per the doc - https://duo.com/docs/splunkapp#distributed-search.
Although, installing the app on a single indexer is not suggested as it can be a single source of failure (meaning if the indexer goes down, you will stop receiving events.
I would suggest option is following order -
1 - Heavy Forwarder
2 - Search Head
3 - Any one Indexer
Please accept the answer if that helps!