Install Splunk Security Essentials
You can install the Splunk Security Essentials app on Splunk Cloud Platform, or you can install it on Splunk Enterprise in a single-instance or distributed environment.
Splunk Security Essentials doesn't interfere with or impact Splunk Enterprise Security. You can safely install Splunk Security Essentials on a Splunk Enterprise Security search head or search head cluster.
Prerequisites
Make sure Splunk Security Essentials is compatible with the version of Splunk Enterprise or Splunk Cloud Platform that you're using. See https://splunkbase.splunk.com/app/3435/ to find the updated compatibility for various Splunk Enterprise, Splunk Cloud Platform, and Splunk Security Essentials versions.
Install on a Splunk Enterprise single-instance deployment
In a single-instance deployment, you can install Splunk Security Essentials on your Splunk Enterprise search head using Splunk Web or a downloaded file.
Install the app using Splunk Web
- Log in to your Splunk Enterprise search head.
- In the Applications menu, select Find More Apps.
- On the Browse More Apps page, select or search for Splunk Security Essentials and click Install.
- Enter your splunk.com credentials.
- Accept the license terms.
- Click Login and Install.
- Click Done.
- Restart Splunk Enterprise to complete the installation.
Install the app from a downloaded file
- Log in to splunkbase.splunk.com.
- Search for and download the Splunk Security Essentials app and save it to an accessible location.
- Log in to your Splunk Enterprise search head.
- On the Apps menu, click Manage Apps.
- On the Apps page, click Install app from file.
- On the Upload app page, click the Choose file button and locate the app in your files.
- Click Upload.
- Click Done.
- Restart Splunk Enterprise to complete the installation.
Install on a Splunk Enterprise distributed deployment
In a distributed deployment, install Splunk Security Essentials on search heads only. This app is safe to install in large clusters because it has no impact on indexers. For installation instructions, see Install an add-on in a distributed Splunk Enterprise deployment in the Splunk Add-ons menu.
Install on Splunk Cloud Platform
You can install Splunk Security Essentials on your Splunk Cloud Platform deployment. For more information, see Install apps in your Splunk Cloud Platform deployment in the Splunk Cloud Platform Admin Manual.
Splunk Security Essentials product compatibility matrix | Uninstall Splunk Security Essentials |
This documentation applies to the following versions of Splunk® Security Essentials: 3.7.1, 3.8.0, 3.8.1
Feedback submitted, thanks!