hRun / SA-haveibeenpwned

Splunk add-on providing a custom search command to query Troy Hunt's haveibeenpwned API (https://haveibeenpwned.com/api/v3/) for known breaches of your domains or mail addresses.
https://splunkbase.splunk.com/app/5050/
Apache License 2.0
6 stars 4 forks source link

Setup Question #4

Closed sddangelo closed 3 years ago

sddangelo commented 3 years ago

Setup notes say to install on the SH- I assume for the knowledge objects. No configuration or API calls being done here - correct?

Since this is making API calls - shouldn't the configuration be done on a HF? The notes don't reference this so I wanted to confirm.

hRun commented 3 years ago

Hi sddangelo,

The add-on should indeed only be installed on the SHs you're planning to use the shipped custom search command on. The search command runs locally after the SHs received intermediate search results from your indexers and queries the HIBP API to enrich these results. Therefore there's no benefit installing the add-on on any other Splunk servers.

Cheers, hRun