Enterprise Security installation

Install Enterprise Security using the Splunk Operator.

The Splunk Operator supports automated installation of Enterprise Security (ES).

Before you begin

  • You need the ability to use the Splunk Operator App Framework method of installation.
  • You need access to the Splunk ES app package.
  • ES support in Splunk Operator starts from Splunk Operator Release 2.2.0, which requires Splunk Enterprise 9.0.3-a2 or higher. Per the Splunk Enterprise and Enterprise Security version compatibility matrix, Splunk ES versions 8.5.1, 8.4.1, 8.4.0, 8.3.0, 8.2.3,8.1.1, 8.1.0, 8.0.2, 7.3.2, 7.1.0, 7.0.2, 7.0.1, 7.0.0, and 6.6.2 are supported.
  • Make sure pod resource specs meet the ES hardware requirements.
  • In the following sections, an AWS S3 remote bucket is used for placing the Splunk apps, but you can also use Azure Blob remote storage as described in the App Framework documentation.
  • You need to deploy add-ons to forwarders manually or through your own methods.
  • You need to deploy Stream App manually.
  • For ES version 7.1 or higher, Behavioral Analytics Service is unavailable for containerized Splunk deployments (supported for cloud releases only).

Supported deployment types

The following components support automated deployment of ES using the Splunk Operator:

  • Standalone Splunk Instance
  • Standalone Search Head with Indexer Cluster
  • Search Head Cluster with Indexer Cluster

If deploying a distributed search environment, the use of indexer clustering is required to ensure that the necessary ES-specific configuration is pushed to the indexers through the Cluster Manager.

What the Splunk Operator automates

The Splunk Operator installs the necessary ES components depending on the architecture specified by the applied CRDs.

Standalone Splunk instances and standalone search heads

For Standalone Splunk instances and standalone search heads, the Operator installs Splunk ES and all associated domain add-ons (DAs) and supporting add-ons (SAs).

Search Head Cluster

When installing ES in a Search Head Cluster, the Operator performs the following tasks:

  1. Installs the Splunk Enterprise app in the Deployer etc/apps directory.
  2. Runs the ES post-install command essinstall that stages the Splunk ES and all associated domain add-ons (DAs) and supporting add-ons (SAs) to etc/shcluster/apps.
  3. Pushes the Search Head Cluster bundle from the deployer to all the search heads.

Indexer Cluster

When installing ES in an indexer clustering environment through the Splunk Operator, you must manually extract and deploy the supplemental Splunk_TA_ForIndexers app from the ES package to the indexer cluster members through the cluster manager. You can achieve this using the AppFramework app deployment steps using an appSources scope of cluster.