Splunk Enterprise

Office 365 logs

tmardan
Explorer

Hello!

How can I add Office 365 logs to my Splunk if I have 1 search head and 2 indexers and using distributed search?

Should I install all add-ons on 1 indexer and make all configurations on it and all add-ons and app on search head?

Labels (1)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

I recommend HF.

Indexers are generally overloaded with requests coming from search head.

You can Install on Indexer if they are not overloaded.

————————————
If this helps, give a like below.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Start by reading the docs for the add-ons and apps you plan to install.  They should say where they want to be installed.

In general, inputs should not be defined on indexers in a distributed environment.  Doing so is likely to cause duplicated data.  Put them on a heavy forwarder, instead.  See https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall

---
If this reply helps you, Karma would be appreciated.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

@tmardan 

exactly.  To separate workloads to different worker machines. 

————————————
If this helps, give a like below.

tmardan
Explorer

As I understood at this moment I can use for it universal forwarder too?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@tmardan 

you can't use UF as it doesn't have python included in package.

————————————
If this helps, give a like below.
0 Karma

tmardan
Explorer

Thank you for answer!

You mean deploy heavy forwarder on another machine and configure it to receive logs from Office365 and then send them to my indexers?

thambisetty
SplunkTrust
SplunkTrust

I recommend HF.

Indexers are generally overloaded with requests coming from search head.

You can Install on Indexer if they are not overloaded.

————————————
If this helps, give a like below.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...