All Apps and Add-ons

Palo Alto Networks Add-on Install Locations

KevinMurray
Explorer

If I have the add-on installed on my heavy forwarder and search heads, is there any need to install it on my indexers as well?????

Labels (1)
0 Karma

ivanreis
Builder

Hi @KevinMurray, in general we usually deploy the add-on on Heavy Forwarder with the inputs.conf setup and for Indexer and Search Head tier without inputs.conf setup. The add-on is being used to normalise data, using the props and transforms.conf, so it is really important to install them

In this particular case, the add-on has a document that highlight "Where to Install" and can be found here:
https://splunk.paloaltonetworks.com/installation.html

I am adding other document where you can have more information where to install Splunk add-ons

https://docs.splunk.com/Documentation/AddOns/released/Overview/Wheretoinstall

Usually the apps and add-ons from Splunk base does have a document with this type of information to assist with.

If this help, please upvote. 

0 Karma

KevinMurray
Explorer

I suspect the add-on is NOT needed on the indexers since I have the add-on with inputs.conf on the heavy forwarder, but, I am going to install it on the indexers anyway without the inputs.conf (obviously)

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...