Splunk Enterprise Security

Recorded Future App Add On for Splunk ES

sifmad23
Engager

I am installing Recorded Future Add on App into my Splunk ES environment I would like to know which Search Head should we install the Recorded Future App. Search head 1 (where Enterprise Security is installed) or Search Head 2 where ES is not installed. My better judgement tells me Search Head 2 however what is the Splunk best practice for this?

Tags (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @sifmad23,

Splunk recommends apps should be installed on other search heads if any. The reason for this is make ES have more available resources.  It is better to install on Search Head 2.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

Hi @sifmad23,

Splunk recommends apps should be installed on other search heads if any. The reason for this is make ES have more available resources.  It is better to install on Search Head 2.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...