<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deployment-Server Linux Sererclass Monitoring Lastlog- Do I need to install on the indexer and on the deployment ser in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Linux-Sererclass-Monitoring-Lastlog-Do-I-need/m-p/614096#M13986</link>
    <description>&lt;P&gt;Hi, thanks for your Reply!&lt;/P&gt;&lt;P&gt;Everything worked, thank you!&lt;/P&gt;&lt;P&gt;I have installed the Linux Unix add-on on the deployment server. Then I moved it from /opt/splunk/etc/apps to /opt/splunk/etc/deployment-apps. After that, I was able to deploy the app via the Splunk web interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings!&lt;/P&gt;</description>
    <pubDate>Thu, 22 Sep 2022 11:22:13 GMT</pubDate>
    <dc:creator>Codyy_Fast</dc:creator>
    <dc:date>2022-09-22T11:22:13Z</dc:date>
    <item>
      <title>Deployment-Server Linux Sererclass Monitoring Lastlog- Do I need to install on the indexer and on the deployment server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Linux-Sererclass-Monitoring-Lastlog-Do-I-need/m-p/612755#M13870</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I am new to Splunk and need a little help.&lt;/P&gt;
&lt;P&gt;I have the following configuration:&lt;/P&gt;
&lt;P&gt;Splunk Indexer Server.&lt;BR /&gt;Splunk Deployment Server.&lt;/P&gt;
&lt;P&gt;I have installed Universal Forwarder on my clients and specified Deployment Server in the installation.&lt;/P&gt;
&lt;P&gt;After installation, the clients report correctly to the Deployment Server. I have created two server classes.&lt;BR /&gt;One for Windows and one for Linux.&lt;/P&gt;
&lt;P&gt;Server class Linux:&lt;/P&gt;
&lt;P&gt;App "fwd_to_receiver" = the Splunk indexer server is specified here.&lt;BR /&gt;App "Linmess" = inputs.conf (here is defined what should be monitored)&lt;/P&gt;
&lt;P&gt;My question now:&lt;/P&gt;
&lt;P&gt;I would like to monitor the /var/log/lastlog file.&lt;BR /&gt;But this does not work with inputs.conf.&lt;/P&gt;
&lt;P&gt;I have now installed a Splunk Add-on for Unix and linux.&lt;BR /&gt;How can I set this up so that my deployment server distributes a central configuration where the "Lastlog" file is monitored correctly and also the source type fits. Do I need to install the add-on on the indexer and on the deployment server?&lt;/P&gt;
&lt;P&gt;Many thanks in advance!&lt;/P&gt;
&lt;P&gt;best regards&lt;BR /&gt;Codyy_Fast&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 15:10:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Linux-Sererclass-Monitoring-Lastlog-Do-I-need/m-p/612755#M13870</guid>
      <dc:creator>Codyy_Fast</dc:creator>
      <dc:date>2022-09-12T15:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment-Server Linux Sererclass Monitoring Lastlog- Do I need to install on the indexer and on the deployment ser</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Linux-Sererclass-Monitoring-Lastlog-Do-I-need/m-p/612819#M13878</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249382"&gt;@Codyy_Fast&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You need to install&amp;nbsp;&lt;SPAN&gt;Splunk Add-on for Unix and linux on your indexers and clients.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For your clients you should enable lastlog input using below inputs.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;$SPLUNK_HOME/etc/deployment-apps/Splunk_TA_nix/local/inputs.conf

[script://./bin/lastlog.sh]
index = your_index
sourcetype = lastlog
source = lastlog
interval = 300
disabled = 0&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 13 Sep 2022 04:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Linux-Sererclass-Monitoring-Lastlog-Do-I-need/m-p/612819#M13878</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2022-09-13T04:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Deployment-Server Linux Sererclass Monitoring Lastlog- Do I need to install on the indexer and on the deployment ser</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Linux-Sererclass-Monitoring-Lastlog-Do-I-need/m-p/614096#M13986</link>
      <description>&lt;P&gt;Hi, thanks for your Reply!&lt;/P&gt;&lt;P&gt;Everything worked, thank you!&lt;/P&gt;&lt;P&gt;I have installed the Linux Unix add-on on the deployment server. Then I moved it from /opt/splunk/etc/apps to /opt/splunk/etc/deployment-apps. After that, I was able to deploy the app via the Splunk web interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Greetings!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2022 11:22:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Deployment-Server-Linux-Sererclass-Monitoring-Lastlog-Do-I-need/m-p/614096#M13986</guid>
      <dc:creator>Codyy_Fast</dc:creator>
      <dc:date>2022-09-22T11:22:13Z</dc:date>
    </item>
  </channel>
</rss>

