splunk

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
splunk [2023/12/22 07:32] – [Install Indexer / Heavy Forwarder] baumisplunk [2024/01/11 09:41] (current) baumi
Line 1: Line 1:
-====== Splunk on Linux ======+====== Splunk Installation ======
  
-===== Install Indexer / Heavy Forwarder =====+==== Install Indexer / Heavy Forwarder ====
 <code> <code>
 sudo useradd -m -d /opt/splunk -s /bin/bash -U splunk && \ sudo useradd -m -d /opt/splunk -s /bin/bash -U splunk && \
Line 9: Line 9:
 </code> </code>
  
-===== Configure Receiver to receive data =====+==== Configure Receiver to receive data ====
 https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Enableareceiver https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Enableareceiver
 <code> <code>
Line 18: Line 18:
 </code> </code>
  
-===== Set-Up Forwarding =====+==== Set-Up Forwarding ====
 https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Deployaheavyforwarder https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Deployaheavyforwarder
 <code> <code>
Line 30: Line 30:
 sudo su -c "/opt/splunk/bin/splunk restart" splunk sudo su -c "/opt/splunk/bin/splunk restart" splunk
 </code> </code>
 +==== Forward to more than one destinations ====
 +/opt/splunk/etc/system/local/outputs.conf
 +<file text outputs.conf>
 +[tcpout]
 +defaultGroup = group1,group2
 +indexAndForward = 0
  
-===== Universal Forwarder =====+[tcpout:group1] 
 +disabled false 
 +server = receiver1:9997 
 + 
 +[tcpout:group2] 
 +disabled = false 
 +server = receiver2:9997 
 +</file> 
 + 
 +==== Universal Forwarder ====
 <code> <code>
 useradd -m -d /opt/splunkforwarder -s /bin/bash -U splunkfwd && \ useradd -m -d /opt/splunkforwarder -s /bin/bash -U splunkfwd && \
Line 39: Line 54:
 </code> </code>
  
-{{tag>linux splunk}}+{{tag>kb linux splunk}}
splunk.1703226763.txt.gz · Last modified: 2023/12/22 07:32 by baumi

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki