<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What's the best way of getting data from our Splunk servers? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306532#M36596</link>
    <description>&lt;P&gt;Yeah that's more or less what I was thinking! Thanks for the reassurance.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2017 13:48:41 GMT</pubDate>
    <dc:creator>Robbie1194</dc:creator>
    <dc:date>2017-10-13T13:48:41Z</dc:date>
    <item>
      <title>What's the best way of getting data from our Splunk servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306530#M36594</link>
      <description>&lt;P&gt;Hi guys, &lt;/P&gt;

&lt;P&gt;Just a few quick questions about getting Splunk server data into splunk! &lt;/P&gt;

&lt;P&gt;Our splunk environment collects a large amount of security data from thousands of sources, yet, we don't collect any security data from the Splunk servers themselves (they run on Redhat linux OS). I was thinking of adding all of our servers (Cluster master, license master, deployer etc) to our deployment server and create a server class with the the *nix TA to ingest the relevant host data we want. Is this the best solution or does anyone have any better ideas on how to do it? &lt;/P&gt;

&lt;P&gt;Also, can the deployment server be a client of itself? How do we get data from it to our indexer cluster if not? &lt;/P&gt;

&lt;P&gt;Is the indexer cluster okay with forwarding data to itself? &lt;/P&gt;

&lt;P&gt;Any help would be appreciated. &lt;/P&gt;

&lt;P&gt;Cheers! &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 13:23:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306530#M36594</guid>
      <dc:creator>Robbie1194</dc:creator>
      <dc:date>2017-10-13T13:23:22Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way of getting data from our Splunk servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306531#M36595</link>
      <description>&lt;P&gt;The indexers (and heavy forwarders) wont need to forward data to themselves. &lt;BR /&gt;
Any applications you install on an indexer/hf will be picked up without having to specify anything in outputs.conf (unless you want to send them to a specific indexer for example) - Just make sure you set your indexes in inputs.conf.&lt;/P&gt;

&lt;P&gt;Deployment servers, Search Heads, and CMs can all be configured to forward events just like any other UF.&lt;BR /&gt;
(But, you cant use a deployment server to manage a deployment server - so you will have to configure that one locally &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; but otherwise, yes, you can push out a configured *nix TA app to collect your interesting data.&lt;/P&gt;

&lt;P&gt;(Beware of enabling ALL the scripted inputs, as they can be a bit intensive.)&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 13:43:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306531#M36595</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-13T13:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way of getting data from our Splunk servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306532#M36596</link>
      <description>&lt;P&gt;Yeah that's more or less what I was thinking! Thanks for the reassurance.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 13:48:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306532#M36596</guid>
      <dc:creator>Robbie1194</dc:creator>
      <dc:date>2017-10-13T13:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way of getting data from our Splunk servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306533#M36597</link>
      <description>&lt;P&gt;A deployment server Splunk instance cannot be a deployment client of itself, but you should be able to install a UF (=a different Splunk instance) on your deployment server to collect local log files and manage that UF with DS. &lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 17:49:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306533#M36597</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-13T17:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way of getting data from our Splunk servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306534#M36598</link>
      <description>&lt;P&gt;I wonder how common of an approach this is? &lt;BR /&gt;
As it happens I have come across just this very scenario today, but I cant see a significant advantage (other than as you note above) as it adds complexity (speaking from someone picking apart an undocumented environment) and increases the number of wtf's per hour before i realised that /opt/splunkforwarder was also on the box. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 18:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306534#M36598</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-13T18:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way of getting data from our Splunk servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306535#M36599</link>
      <description>&lt;P&gt;@ssievert - what is your opinion of having the deployment server have the needed apps deployed to it without it actually being a deployment client (rather than a UF installed in parallel)? This might be implemented with symlinks, rsynch, or just a duplicate copy of the app from the &lt;CODE&gt;deployment-apps&lt;/CODE&gt; folder to the deployment server's &lt;CODE&gt;apps&lt;/CODE&gt; folder.&lt;/P&gt;

&lt;P&gt;Thoughts? Any technical challenges? Or is it just easier to maintain by having the UF installed, hence that suggestion.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 12:48:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306535#M36599</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2017-10-18T12:48:09Z</dc:date>
    </item>
    <item>
      <title>Re: What's the best way of getting data from our Splunk servers?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306536#M36600</link>
      <description>&lt;P&gt;That should be fine. &lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2017 17:20:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/What-s-the-best-way-of-getting-data-from-our-Splunk-servers/m-p/306536#M36600</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-10-18T17:20:12Z</dc:date>
    </item>
  </channel>
</rss>

