All Apps and Add-ons

In a distributed Splunk environment, should Trend Micro Deep Security app be installed on heavy forwarders and indexers, as well as search heads?

PhilipShaunTayl
New Member

TM Deep Security app has index-time transforms in transforms.conf.

0 Karma
1 Solution

Grumpalot
Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

View solution in original post

0 Karma

Grumpalot
Communicator

@PhilipShaunTaylor, yes you will install this on all 3. The HF version will need a inputs.conf (and outputs.conf) if one is already not setup. You can turn the UI off for the App if you do not want to see it on the left bar. Same can be done for the Index/er's which will use props/transforms. The Search Head/s will utilize the savedsearches/tags/eventtypes.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...