GithubHelp home page GithubHelp logo

Comments (7)

paulmnguyen avatar paulmnguyen commented on September 22, 2024 1

Hello,

The add-on should be installed everywhere except for Universal Forwarders. If you are using a Heavy forwarder then it needs to be installed there too.

Where to install

Splunk Node What to install
Search Head Add-on and App
Indexer Add-on only
Heavy Forwarder Add-on only
Universal Forwarder None

https://splunk.paloaltonetworks.com/installation.html

from splunk-apps.

welcome-to-palo-alto-networks avatar welcome-to-palo-alto-networks commented on September 22, 2024

πŸŽ‰ Thanks for opening your first issue here! Welcome to the community!

from splunk-apps.

lamonica-a avatar lamonica-a commented on September 22, 2024

@paulmnguyen

Is this also the case for a Single Instance Splunk Environment?

Also, could I configure this with just the Add-on installed on the Search head & Indexer, and not have the App installed on the Search head?

from splunk-apps.

paulmnguyen avatar paulmnguyen commented on September 22, 2024

Yes, that is correct only the TA is needed for parsing. I'm not sure I understand your question in regards to the single instance environment.

from splunk-apps.

lamonica-a avatar lamonica-a commented on September 22, 2024

@paulmnguyen
https://docs.splunk.com/Documentation/Splunk/9.0.4/Overview/AboutSplunkEnterprisedeployments

Single-instance deployments
In small deployments, one instance of Splunk Enterprise handles all aspects of processing data, from input through indexing to search. A single-instance deployment can be useful for testing and evaluation purposes and might serve the needs of department-sized environments.

Distributed deployments
To support larger environments where data originates on many machines, where you need to process large volumes of data, or where many users need to search the data, you can scale the deployment by distributing Splunk Enterprise instances across multiple machines. This is known as a "distributed deployment".

In a typical distributed deployment, each Splunk Enterprise instance performs a specialized task and resides on one of three processing tiers corresponding to the main processing functions:

Data input tier
Indexer tier
Search management tier

from splunk-apps.

lamonica-a avatar lamonica-a commented on September 22, 2024

@paulmnguyen
Also, my SA confirmed that the Add-on is on all indexers located in β€œSlave Apps”, and are installed on the search heads per the instructions for the Add-on.

What could be the issue?

from splunk-apps.

paulmnguyen avatar paulmnguyen commented on September 22, 2024

Try running a search fro pan:* but set the time to "All Time"

from splunk-apps.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.