Splunk Enterprise

Office 365 logs

tmardan
Explorer

Hello!

How can I add Office 365 logs to my Splunk if I have 1 search head and 2 indexers and using distributed search?

Should I install all add-ons on 1 indexer and make all configurations on it and all add-ons and app on search head?

Labels (1)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

I recommend HF.

Indexers are generally overloaded with requests coming from search head.

You can Install on Indexer if they are not overloaded.

————————————
If this helps, give a like below.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Start by reading the docs for the add-ons and apps you plan to install.  They should say where they want to be installed.

In general, inputs should not be defined on indexers in a distributed environment.  Doing so is likely to cause duplicated data.  Put them on a heavy forwarder, instead.  See https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall

---
If this reply helps you, Karma would be appreciated.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

@tmardan 

exactly.  To separate workloads to different worker machines. 

————————————
If this helps, give a like below.

tmardan
Explorer

As I understood at this moment I can use for it universal forwarder too?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@tmardan 

you can't use UF as it doesn't have python included in package.

————————————
If this helps, give a like below.
0 Karma

tmardan
Explorer

Thank you for answer!

You mean deploy heavy forwarder on another machine and configure it to receive logs from Office365 and then send them to my indexers?

thambisetty
SplunkTrust
SplunkTrust

I recommend HF.

Indexers are generally overloaded with requests coming from search head.

You can Install on Indexer if they are not overloaded.

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...