Install the Splunk Add-on for McAfee on your search heads
To install the Splunk Add-on for McAfee that does not run inputs on search heads in a Splunk Enterprise deployment, download the add-on from Splunkbase and then complete the following steps:
- From the Splunk Web home screen, click the gear icon next to Apps.
- Click Install app from file.
- Locate the downloaded file and click Upload.
- If Splunk Enterprise prompts you to restart, do so.
- From the Splunk Web home screen, click the gear icon next to Apps.
- Find the add-on and click Edit properties.
- Change Visible to No.
You can verify your installation was successful by finding the Splunk Add-on for McAfee at $SPLUNK_HOME/etc/apps/Splunk_TA_mcafee
.
Install the Splunk Add-on for McAfee onto your heavy forwarder | Install the Add-on for McAfee onto your search head cluster |
This documentation applies to the following versions of Splunk® Enterprise: 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.0.7, 8.0.8, 8.0.9, 8.0.10
Feedback submitted, thanks!