Splunk Enterprise Security

Does Splunk ES need the add-on and app or just the add-on?

mikefg
Communicator

Working on a new ES install. Does the ES search head need the app and add-on for each technology or just the add-on? Does it matter if the app and add-on are both installed?

0 Karma
1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

... so you would have to download the ones that you need from Splunkbase instead. 

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES doesn't exist without the app so it must be installed.  As part of the installation process, you will be asked to choose the add-ons you need.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mikefg
Communicator

I understand that the ES app itself is needed, my question is about the rest of the technologies; firewalls, etc. As I understand it I only need to install the add-on for these on the ES search head and not the app, unless I want to use the app on the ES search head, correct?

I went through the install and I don't remember a step asking me about choosing add-ons. Fresh install of ES 6.4.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct.  You only need the TAs and not the apps.

---
If this reply helps you, Karma would be appreciated.
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

... so you would have to download the ones that you need from Splunkbase instead. 

0 Karma

mikefg
Communicator

Gotcha, thanks!

0 Karma
Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...