Splunk Enterprise Security

How do I configure Splunk Enterprise Security in an indexer cluster?

mgalos
New Member

I am not sure which Splunk ES related apps go where.

My deployment looks like the following:

Splunk universal forwarder (windows/linux/) + syslog ===> 2 Heavy Forwarders =====> 2 Indexers ======> 1 search head/master

I deployed the OS related TA app on the UF and the ES app config on the search head/mater. I am not sure where any of the SA or DA files need to go in addition to this.

Do i need to copy the app files into the indexers as well?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

ES should be on a dedicated search head. It's too demanding of resources to share a box with adhoc searches and cluster master.

Yes, TAs need to be installed on the indexers.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...