Splunk® Supported Add-ons

Splunk Add-on for Amazon Kinesis Firehose

Acrobat logo Download manual as PDF


Acrobat logo Download topic as PDF

Select and prepare your distributed Splunk Enterprise deployment for the Splunk Add-on for Amazon Kinesis Firehose

Before you install the Splunk Add-on for Amazon Kinesis Firehose on a distributed Splunk Enterprise, review the supported deployment topologies below. The diagrams show where the Splunk Add-on for Amazon Kinesis Firehose should be installed for data collection in the supported distributed deployment topologies. The add-on is also installed on search heads for search-time functionality, but that is not shown in the diagrams.

Choose the deployment topology that works best for your situation.

Indexers in AWS VPC

If your indexers are on AWS Virtual Private Cloud, use an elastic load balancer to send data to your indexers. Firehose-to-VPC.png

Next step
Configure an Elastic Load Balancer for the Splunk Add-on for Amazon Kinesis Firehose

Indexers not in an AWS VPC

If your indexers are not in an AWS VPC, but are accessible from AWS Firehose via public IPs, install a CA-signed SSL certificate on each indexer, then send data directly to your indexers.

Firehose-to-IDX.png

Prepare your indexers before you proceed:

  1. Install a CA-signed SSL certificate on each indexer. For instructions, see Configure your indexer to use your certificates in Securing Splunk Enterprise.
  2. Create a DNS name that resolves to the set of indexers that you plan to use to collect data from Amazon Kinesis Firehose. You will need this DNS name in a later step.

Next step
Install the Splunk Add-on for Amazon Kinesis Firehose on a distributed Splunk Enterprise deployment

Last modified on 08 October, 2021
PREVIOUS
Installation steps for the Splunk Add-on for Amazon Kinesis Firehose on a distributed Splunk Enterprise deployment
  NEXT
Configure an Elastic Load Balancer for the Splunk Add-on for Amazon Kinesis Firehose

This documentation applies to the following versions of Splunk® Supported Add-ons: released, released


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters