User Tools

Site Tools


splunk

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
splunk [2023/12/22 07:32] – [Install Indexer / Heavy Forwarder] baumisplunk [2024/01/11 09:41] (current) baumi
Line 1: Line 1:
-====== Splunk on Linux ======+====== Splunk Installation ======
  
-===== Install Indexer / Heavy Forwarder =====+==== Install Indexer / Heavy Forwarder ====
 <code> <code>
 sudo useradd -m -d /opt/splunk -s /bin/bash -U splunk && \ sudo useradd -m -d /opt/splunk -s /bin/bash -U splunk && \
Line 9: Line 9:
 </code> </code>
  
-===== Configure Receiver to receive data =====+==== Configure Receiver to receive data ====
 https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Enableareceiver https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Enableareceiver
 <code> <code>
Line 18: Line 18:
 </code> </code>
  
-===== Set-Up Forwarding =====+==== Set-Up Forwarding ====
 https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Deployaheavyforwarder https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Deployaheavyforwarder
 <code> <code>
Line 30: Line 30:
 sudo su -c "/opt/splunk/bin/splunk restart" splunk sudo su -c "/opt/splunk/bin/splunk restart" splunk
 </code> </code>
 +==== Forward to more than one destinations ====
 +/opt/splunk/etc/system/local/outputs.conf
 +<file text outputs.conf>
 +[tcpout]
 +defaultGroup = group1,group2
 +indexAndForward = 0
  
-===== Universal Forwarder =====+[tcpout:group1] 
 +disabled false 
 +server = receiver1:9997 
 + 
 +[tcpout:group2] 
 +disabled = false 
 +server = receiver2:9997 
 +</file> 
 + 
 +==== Universal Forwarder ====
 <code> <code>
 useradd -m -d /opt/splunkforwarder -s /bin/bash -U splunkfwd && \ useradd -m -d /opt/splunkforwarder -s /bin/bash -U splunkfwd && \
Line 39: Line 54:
 </code> </code>
  
-{{tag>linux splunk}}+{{tag>kb linux splunk}}
splunk.1703226763.txt.gz · Last modified: 2023/12/22 07:32 by baumi

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki