The installation process for the Tenable App for Splunk and Tenable Add-On for Splunk varies based on your Splunk environment.
Single-server, distributed deployment, and cloud instance options are available.
In a single-server deployment, a single instance of Splunk Enterprise works as a data collection node, indexer, and search head. In this instance, install the Tenable Add-On and Tenable App on this node. Complete the setup for the Tenable Add-On to start data collection.
In a distributed deployment, install Splunk on at least two instances. One node works as a search head, while the other node works as an indexer for data collection.
The following table displays Tenable Add-On and Tenable App installation information in the distributed environment.
|Tenable Add-on for Splunk (TA-Tenable)||
|Tenable-SC App for Splunk (Tenable App)||No||No||Yes|
In Splunk Cloud, the data indexing takes place in a cloud instance.
Note: The data collection can take place in an on-premise Splunk instance that works as a heavy forwarder.
You can install the application via a command line, or from the Splunk user interface.