Splunk Enterprise Security

How to use a heavy forwarder to collect asset and identity information for Splunk Enterprise Security on Splunk Cloud?

jgorman_THG
Explorer

HI!

I'm following the following directions to try and set up assets and identities for Splunk Enterprise Security on Splunk Cloud through a heavy forwarder.

https://www.hurricanelabs.com/blog/gathering-ldap-identity-data-with-splunk-cloud

The instructions say to set up a saved search on the Heavy Forwarder and have it populate a summary index. However, I am unable to schedule searches on the Heavy Forwarder and get the message:

The search scheduler is disabled by
the license Splunk is using. Scheduled
searches that populate a summary index
were found, but they will not be
executed. This might affect dashboard
panels that depend on the summary
index.
[!/help?location=learnmore.license.features
Learn more]

Does anyone have any tips on what I am missing?

Thanks,

JG

0 Karma

amir_ma
Loves-to-Learn

Hi I am using free trial of splunk I am dealing with this problem too with universal or heavy forwarder and I can't even open a ticket.

splunk.pngsearch_head.png

Thanks

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Open a ticket with Support, and explain what you are trying to do. They will get you a 1mb license that enables the deployment server and other enterprise features. (These are available for 30 days after installing, but then rolls to limited license.)

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...