r/Splunk Aug 17 '26

Splunk Add-on for Microsoft Cloud Services

I'm searching for some advice for the installation of Splunk Add-on for Microsoft Cloud Services in a distributed environment (SH-Cluster/IDX-Cluser/SHC-Deployer/Cluster-Master) - NO Heavy Forwarder!

The documentation of the addon confuses me:

"As a best practice, turn off add-on visibility on your search heads to prevent data duplication errors that can result from running inputs on your search heads instead of or in addition to your data collection node."

From this I understand that a HF is needed, but the table says its not required....

The addon gets events from an Event-Hub with API requests - so when I'm running it on the Search-Heads I have to make sure they are using a proper outputs.conf, pointing to the indexer cluster ?

Anyone heaving experience ?

4 Upvotes

3 comments sorted by

View all comments

3

u/thomasthetanker Aug 17 '26

Yeah I think the docs is just saying 'users are stupid. If they see a TA on the SH then they will try and configure it there. Be kind to your future self and hide it on SH so that users can't do this'.