All Apps and Add-ons

Where do I install the FireEye Add-on for Splunk Enterprise?

gerald_contrera
Path Finder

Hi all,

We currently have
4- indexer peers
1- heavy forwarder which forwards FireEye logs (which syslog to a folder and is monitored by HF) to splunk.
- FireEye EX and soon NX

I have installed the FireEye-App on the search heads, and currently have the Add-on/TA on the heavy forwarder.
Can anyone confirm if i have to install the add-on/TA on the indexers also?

Any help would be great, there is a lot of doco on the FireEye App, but not much on the Add-on/TA.

We are currently getting some basic data in the App. But i would have expected more?

Thanks in advance

0 Karma
1 Solution

gerald_contrera
Path Finder

Answered my own.
Looks like I had to make sure I was using the right source type for this to work.

Used custom folder monitor syslog events ensuring to use fe sourcetype. Installed app on SH.

View solution in original post

0 Karma

gerald_contrera
Path Finder

Answered my own.
Looks like I had to make sure I was using the right source type for this to work.

Used custom folder monitor syslog events ensuring to use fe sourcetype. Installed app on SH.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...