Splunk Enterprise Security

Does Splunk ES need the add-on and app or just the add-on?

mikefg
Path Finder

Working on a new ES install. Does the ES search head need the app and add-on for each technology or just the add-on? Does it matter if the app and add-on are both installed?

0 Karma
1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

... so you would have to download the ones that you need from Splunkbase instead. 

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES doesn't exist without the app so it must be installed.  As part of the installation process, you will be asked to choose the add-ons you need.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

mikefg
Path Finder

I understand that the ES app itself is needed, my question is about the rest of the technologies; firewalls, etc. As I understand it I only need to install the add-on for these on the ES search head and not the app, unless I want to use the app on the ES search head, correct?

I went through the install and I don't remember a step asking me about choosing add-ons. Fresh install of ES 6.4.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct.  You only need the TAs and not the apps.

---
If this reply helps you, an upvote would be appreciated.
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

... so you would have to download the ones that you need from Splunkbase instead. 

0 Karma

mikefg
Path Finder

Gotcha, thanks!

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...