In the distributed deployment scheme, you must install Forwarder App and Search Head App on the basis of the organization of your distributed Splunk environment. For more information about how to choose the computers where the apps must be installed, see section "About the distributed integration scheme".
Forwarder App is installed from the %service_dir%/integration/Kaspersky-CyberTrace-App-for-Splunk_Forwarder.tar.gz
file. Search Head App is installed from the %service_dir%/integraion/Kaspersky-CyberTrace-App-for-Splunk_Search-Head.tar.gz
file.
Installing the apps
Forwarder App and Search Head App are installed from Splunk Web. The only difference in the installation process is the application file name.
To install Forwarder App or Search Head App:
Manage Apps button
Install app from file button
Choose File button
Upload button
This step can be skipped, depending on the Splunk version. If Splunk does not display the Restart required window, skip this step.
Restart Splunk button
Kaspersky Search Head App for Splunk in the list of apps