User Tools

Site Tools


splunk

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
splunk [2023/12/22 07:34] – [Set-Up Forwarding] baumisplunk [2024/01/11 09:41] (current) baumi
Line 1: Line 1:
-====== Splunk on Linux ======+====== Splunk Installation ======
  
-===== Install Indexer / Heavy Forwarder =====+==== Install Indexer / Heavy Forwarder ====
 <code> <code>
 sudo useradd -m -d /opt/splunk -s /bin/bash -U splunk && \ sudo useradd -m -d /opt/splunk -s /bin/bash -U splunk && \
Line 9: Line 9:
 </code> </code>
  
-===== Configure Receiver to receive data =====+==== Configure Receiver to receive data ====
 https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Enableareceiver https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Enableareceiver
 <code> <code>
Line 18: Line 18:
 </code> </code>
  
-===== Set-Up Forwarding =====+==== Set-Up Forwarding ====
 https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Deployaheavyforwarder https://docs.splunk.com/Documentation/Splunk/9.1.2/Forwarding/Deployaheavyforwarder
 <code> <code>
Line 32: Line 32:
 ==== Forward to more than one destinations ==== ==== Forward to more than one destinations ====
 /opt/splunk/etc/system/local/outputs.conf /opt/splunk/etc/system/local/outputs.conf
-<code>+<file text outputs.conf>
 [tcpout] [tcpout]
 defaultGroup = group1,group2 defaultGroup = group1,group2
Line 44: Line 44:
 disabled = false disabled = false
 server = receiver2:9997 server = receiver2:9997
-</code>+</file>
  
-===== Universal Forwarder =====+==== Universal Forwarder ====
 <code> <code>
 useradd -m -d /opt/splunkforwarder -s /bin/bash -U splunkfwd && \ useradd -m -d /opt/splunkforwarder -s /bin/bash -U splunkfwd && \
Line 54: Line 54:
 </code> </code>
  
-{{tag>linux splunk}}+{{tag>kb linux splunk}}
splunk.1703226880.txt.gz · Last modified: 2023/12/22 07:34 by baumi

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki