Install the Splunk Add-on for OSSEC
- Get the Splunk Add-on for OSSEC by downloading it from https://splunkbase.splunk.com/app/2808 or browsing to it using the app browser within Splunk Web.
- Perform any prerequisite steps before installing, if required.
- In a distributed, on-premises deployment, install the Splunk Add-on for OSSEC to your search heads and forwarders. This add-on does not need to be installed on indexers.
- Complete your installation.
If you need step-by-step instructions on how to install an add-on in your specific deployment environment, see the installation walkthroughs section at the bottom of this page for links to installation instructions specific to a single-instance deployment, distributed deployment, Splunk Cloud, or Splunk Light.
The Splunk Add-Ons manual includes an Installing add-ons guide that helps you successfully install any Splunk-supported add-on to your Splunk platform.
For a walkthrough of the installation procedure, follow the link that matches your deployment scenario:
Installation and configuration overview for the Splunk Add-on for OSSEC
Upgrade the Splunk Add-on for OSSEC
This documentation applies to the following versions of Splunk® Supported Add-ons: released