Security & the Enterprise
Much secured. So patch!

ES 6.4 Fresh Install

mikefg
Path Finder

I am working on a fresh install of ES 6.4. I already have a Splunk Ent environment with an indexer tier, apps, single search head, etc. ES has been installed on a standalone search head, but not configured. I have configured ES before, but it was a few versions and a few years back. 

What are some good resources to get ES configured besides the install docs?

Since I already have a Splunk environment with forwarders, add-ons, etc. it looks like my next step might be 'Create the Splunk_TA_ForIndexers and manage deployment manually'. If I go to this step am I skipping something I shouldn't skip?
https://docs.splunk.com/Documentation/ES/6.4.0/Install/InstallTechnologyAdd-ons

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You may want to send those configurations separately, especially in a indexer cluster.

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Follow all of the steps in that document (except those pertaining to search head clusters) and you should be fine.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

mikefg
Path Finder

This helps. One question on the TA For Indexers. Why are these two settings optional when downloading the package?

   Include index time properties
   Include index definitions

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You may want to send those configurations separately, especially in a indexer cluster.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...