All Apps and Add-ons

[Protocol Data Inputs] Where to install the add-on ?

SirHill17
Communicator

Hi,

I would like to use the add-on Protocol Data Inputs but I am unsure where should it be installed (meaning if it must be on every indexer part of a cluster --> master server ?) Or install on a dedicated server like Heavy Forwarder.

Thanks for your help.

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Install on a Forwarder.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

Install on a Forwarder.

0 Karma

SirHill17
Communicator

Thanks for your quick answer.
I have another question following your answer. My aim is to have a centralized component masking data for all my servers (+2000) so if I can avoid deploying the add-on on every single host is better and also not impacting the servers where the forwarders run. Do you think it's possible to install the add-on on a Heavy Forwarder and having the UF sending the data to this HF which will handle the data ?

0 Karma

Damien_Dallimor
Ultra Champion

Yes that is possible.
UF -> forward raw TCP -> PDI App's TCP Port running on HF

SirHill17
Communicator

Thanks for your help.

0 Karma

Damien_Dallimor
Ultra Champion

My pleasure , shout out if you need any more help with custom handlers etc.. (I wrote the app).

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...