u/mr_networkrobot

▲ 4 r/Splunk

Splunk Add-on for Microsoft Cloud Services

I'm searching for some advice for the installation of Splunk Add-on for Microsoft Cloud Services in a distributed environment (SH-Cluster/IDX-Cluser/SHC-Deployer/Cluster-Master) - NO Heavy Forwarder!

The documentation of the addon confuses me:

"As a best practice, turn off add-on visibility on your search heads to prevent data duplication errors that can result from running inputs on your search heads instead of or in addition to your data collection node."

From this I understand that a HF is needed, but the table says its not required....

The addon gets events from an Event-Hub with API requests - so when I'm running it on the Search-Heads I have to make sure they are using a proper outputs.conf, pointing to the indexer cluster ?

Anyone heaving experience ?

reddit.com
u/mr_networkrobot — 3 days ago
▲ 8 r/Splunk

How do you use Splunk Enterprise Security ?

Just want to know how people use ES in real world.
On a distributed environment the usage seems to have a huge operational expense.
For example:
Reading every potential usefull detection.
Normalize events/data modify datamodels etc.
Create a custom app and clone every needed detection into it (because any change in a detection which is originated in ESCU or ES app, will create a clone in /local/savesearches.conf and next ES-ContentUpdate will potentially create inconsistency ).
Testing every single detection.
The use case library is not useful for this because it does not see the cloned/customized detections.
Not even talking about versioning ....

reddit.com
u/mr_networkrobot — 17 days ago