Hi,
It's good to install Splunk Enterprise on server separately from DenyAll server.
The path to install Splunk Enterprise can be default or changed during installation process.
After installation of DenyAll app into Splunk Enterprise, I'd highly recommend you to ensure the sysylog port 514 (UDP) is opened in Splunk server, as DenyAll server will send syslog events using port 514 (as I noticed that I can't changed the Port in DenyAll console).
The dashboard and events will not work in Splunk due to inability to open port 514 in Splunk server, especially on CentOS or Linux, due to inability to open port 514 if you run/start Splunk using non-root user.
All the best. Cheers !
... View more