Splunk Enterprise

General AV Exclusions on Windows Servers with Splunk

MSTM
New Member

Hello all,

I was hoping that someone might know where I can find the AV scan exclusions I would need to have AV on the same server as Splunk. In particular, I'm looking for the file, folder, process, and service exclusions that should be made in order to Splunk without issue.

Tags (1)
0 Karma

jaxjohnny2000
Builder

davebrooking
Contributor
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk advises excluding all of $SPLUNK_HOME and $SPLUNK_DB from AV scans.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...