Splunk Enterprise Security

Does Splunk ES need the add-on and app or just the add-on?

mikefg
Communicator

Working on a new ES install. Does the ES search head need the app and add-on for each technology or just the add-on? Does it matter if the app and add-on are both installed?

0 Karma
1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

... so you would have to download the ones that you need from Splunkbase instead. 

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES doesn't exist without the app so it must be installed.  As part of the installation process, you will be asked to choose the add-ons you need.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mikefg
Communicator

I understand that the ES app itself is needed, my question is about the rest of the technologies; firewalls, etc. As I understand it I only need to install the add-on for these on the ES search head and not the app, unless I want to use the app on the ES search head, correct?

I went through the install and I don't remember a step asking me about choosing add-ons. Fresh install of ES 6.4.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Correct.  You only need the TAs and not the apps.

---
If this reply helps you, Karma would be appreciated.
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee
0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

... so you would have to download the ones that you need from Splunkbase instead. 

0 Karma

mikefg
Communicator

Gotcha, thanks!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...