Splunk Enterprise Security

Splunk Azure Deployment questions

adalbor
Builder

Hey All,

We are researching a potential Splunk deployment to the Azure cloud but had a few questions.

In the documentation listed on the blog "Announcing Splunk Enterprise in Microsoft Azure Marketplace" there is a diagram listing proposed topology. I notice that there is no mention of an ES server but an on-prem deployment would require one. Am I missing something here? Are there components that can't run in Azure that run in an on-prem setup? Do we lose any features by deploying there?

Thanks!
Andrew

0 Karma

woodcock
Esteemed Legend

Design the architecture that you would like (make sure to include firewall/port details), hand it off to your Azure team and they will create the servers for you. Treat the servers just like any other physical server. You can deploy any Splunk infrastructure, including ES, in Azure. We have done so.

0 Karma

jconger
Splunk Employee
Splunk Employee

The blog post mentioned centers around deploying Splunk Enterprise in Azure via the Azure Marketplace. Splunk Enterprise is a prerequisite for Enterprise Security. You can use the Azure Marketplace deployment to first deploy Splunk and then install Enterprise Security if you like.

There are some things to think about when deploying Splunk in Azure though. Things like managed disks, availability sets, instance size, etc. A white paper is available if you want to look at some of those details. This white paper details deploying Splunk in Azure manually instead of using the Azure Marketplace method.

0 Karma

adalbor
Builder

Thanks for the link, I have seen that one. Just without a mention of the ES I was quite curious.

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @adalbor

This looks like just a documentation issue. There is no problem with running ES in your Azure cloud.

Cheers, Chris

0 Karma

adalbor
Builder

Do you have or know of where I could find documentation detailing the entire deployment?

0 Karma

chrisyounger
SplunkTrust
SplunkTrust

Hi @adalbor, There is really nothing that is unique to Azure. Use the marketplace to deploy the base Splunk images (or otherwise install base product yourself), and then just put ES on top following the normal, documented install process.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...