Splunk Enterprise

Office 365 logs

tmardan
Explorer

Hello!

How can I add Office 365 logs to my Splunk if I have 1 search head and 2 indexers and using distributed search?

Should I install all add-ons on 1 indexer and make all configurations on it and all add-ons and app on search head?

Labels (1)
0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

I recommend HF.

Indexers are generally overloaded with requests coming from search head.

You can Install on Indexer if they are not overloaded.

————————————
If this helps, give a like below.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Start by reading the docs for the add-ons and apps you plan to install.  They should say where they want to be installed.

In general, inputs should not be defined on indexers in a distributed environment.  Doing so is likely to cause duplicated data.  Put them on a heavy forwarder, instead.  See https://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall

---
If this reply helps you, Karma would be appreciated.
0 Karma

thambisetty
SplunkTrust
SplunkTrust

@tmardan 

exactly.  To separate workloads to different worker machines. 

————————————
If this helps, give a like below.

tmardan
Explorer

As I understood at this moment I can use for it universal forwarder too?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

@tmardan 

you can't use UF as it doesn't have python included in package.

————————————
If this helps, give a like below.
0 Karma

tmardan
Explorer

Thank you for answer!

You mean deploy heavy forwarder on another machine and configure it to receive logs from Office365 and then send them to my indexers?

thambisetty
SplunkTrust
SplunkTrust

I recommend HF.

Indexers are generally overloaded with requests coming from search head.

You can Install on Indexer if they are not overloaded.

————————————
If this helps, give a like below.
Get Updates on the Splunk Community!

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...