splunk
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| splunk [2023/11/29 16:56] – [Configure Receiver to receive data] baumi | splunk [2024/01/11 09:41] (current) – baumi | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== Splunk | + | ====== Splunk |
| - | ===== Install Indexer / Heavy Forwarder | + | ==== Install Indexer / Heavy Forwarder ==== |
| < | < | ||
| - | sudo useradd -m -d / | + | sudo useradd -m -d /opt/splunk -s / |
| - | sudo chsh -s /bin/bash splunk && \ | + | |
| sudo tar xzvf ~/ | sudo tar xzvf ~/ | ||
| sudo chown -R splunk: | sudo chown -R splunk: | ||
| Line 10: | Line 9: | ||
| </ | </ | ||
| - | ===== Configure Receiver to receive data ===== | + | ==== Configure Receiver to receive data ==== |
| https:// | https:// | ||
| < | < | ||
| Line 16: | Line 15: | ||
| export password=password | export password=password | ||
| export port=9997 | export port=9997 | ||
| - | sudo su -c "/ | + | sudo su -c "/ |
| </ | </ | ||
| - | ===== Set-Up Forwarding | + | ==== Set-Up Forwarding ==== |
| https:// | https:// | ||
| < | < | ||
| Line 28: | Line 27: | ||
| sudo su -c "/ | sudo su -c "/ | ||
| sudo su -c "/ | sudo su -c "/ | ||
| - | sudo su -c " | + | sudo su -c " |
| sudo su -c "/ | sudo su -c "/ | ||
| </ | </ | ||
| + | ==== Forward to more than one destinations ==== | ||
| + | / | ||
| + | <file text outputs.conf> | ||
| + | [tcpout] | ||
| + | defaultGroup = group1, | ||
| + | indexAndForward = 0 | ||
| - | ===== Universal Forwarder | + | [tcpout: |
| + | disabled | ||
| + | server = receiver1: | ||
| + | |||
| + | [tcpout: | ||
| + | disabled = false | ||
| + | server = receiver2: | ||
| + | </ | ||
| + | |||
| + | ==== Universal Forwarder ==== | ||
| < | < | ||
| - | useradd -m -d / | + | useradd -m -d / |
| - | chsh -s /bin/bash splunkfwd && \ | + | |
| sudo tar xzvf ~/ | sudo tar xzvf ~/ | ||
| sudo chown -R splunkfwd: | sudo chown -R splunkfwd: | ||
| Line 41: | Line 54: | ||
| </ | </ | ||
| - | {{tag> | + | {{tag>kb linux splunk}} |
splunk.1701273388.txt.gz · Last modified: by baumi
