Installation

Question about Fortinet FortiGate Add-On for Splunk in splunkbase.com platform?

badr_boukari
Explorer

Hello the Team, hope you are Okey!

 

I have a question about Fortinet FortiGate Add-On for Splunk which is available in splunkbase.com platform : https://splunkbase.splunk.com/app/2846/#/details.

I am deploying a distributed Splunk Enterprise infrastructure with a Heavy Forwarder, Indexer and Search Head. I don’t know exactly in which instance I should  install the add-on?

Is it in the search Head? Should I add data input on Heavy Forwarder Instance? I didn’t really find a clear procedure for the installation and the configuration.

 

I have to implement a BOSS Of The SoC environment (so the datasets are already available on GitHub web site)

 

Thanks, In advance.

Waiting for your response,

Labels (4)
0 Karma

Imad
Engager

My setup:

Search Head Cluster with Deployer

Indexer Cluster with Cluster Manager

 

Fortigate Add-on: Installed on Fortigate Search Head Cluster AND Fortigate Indexer Cluster. So the Add-on needs to go on both SH cluster and Indexer cluster.

 

Fortigate App: Installed only on the Search Head Cluster.

 

Hope this helps.

 

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...