Splunk Enterprise Security

Splunk Enterprise Security & Transit Heavy-Forwarder

Splunker
Communicator

Folks,

In the following Splunk installation [SH -> IDX -> Heavy-Forwarder -> Multiple UFs + Syslog]

Using Enterprise Security. I understand i need to install the main app on the SH, and TA- directories on the Indexers (technically any TA's that have index-time operations), do i also need to deploy the TA- apps on my transit Heavy-Forwarders as well?

I assume no, but thought i'd check to be sure..

Thanks.

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Yes, you do actually. Some of the index-time operations will be performed there instead of on the indexer, so they will require that configurations. More info here: http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

Yes, you do actually. Some of the index-time operations will be performed there instead of on the indexer, so they will require that configurations. More info here: http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F

Splunker
Communicator

Thanks gkanapathy. That makes sense. Another reason i should setup the deployment-server to keep it all in sync.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...