<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: check if splunk is installed on linux systems and the process name in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705073#M20908</link>
    <description>&lt;P&gt;They should.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2024 17:07:41 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-11-22T17:07:41Z</dc:date>
    <item>
      <title>check if splunk is installed on linux systems and the process name</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705043#M20900</link>
      <description>&lt;P&gt;i need to run a script to check if a list of linux servers have splunk installed and the process name. any idea what the process name is or the installed directory? and if its forwarding to splunk console?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 15:00:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705043#M20900</guid>
      <dc:creator>LinkLoop</dc:creator>
      <dc:date>2024-11-22T15:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: check if splunk is installed on linux systems and the process name</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705069#M20906</link>
      <description>&lt;P&gt;The default installation directory for Splunk Enterprise is &lt;FONT face="courier new,courier"&gt;/opt/splunk&lt;/FONT&gt; and for the Universal Forwarder it's &lt;FONT face="courier new,courier"&gt;/opt/splunkforwarder&lt;/FONT&gt;.&amp;nbsp; Both can be changed during installation so those are not 100% reliable.&lt;/P&gt;&lt;P&gt;The Splunk process name is 'splunkd'.&lt;/P&gt;&lt;P&gt;As for whether it is forwarding to Splunk, that's a bit trickier.&amp;nbsp; You could issue a &lt;FONT face="courier new,courier"&gt;splunk list forward-server&lt;/FONT&gt; command, but you'd need execute access on the splunk binary and a Splunk account.&lt;/P&gt;&lt;P&gt;Another option is to use the &lt;FONT face="courier new,courier"&gt;splunk btool outputs list&lt;/FONT&gt; command to see if there is a server setting.&amp;nbsp; There may be more than one, however, and zero or more may be in effect.&lt;/P&gt;&lt;P&gt;Consider using network tools to see if splunk has an open connection to port 9997 or 9998.&amp;nbsp; That's a good test for forwarding.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 16:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705069#M20906</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-11-22T16:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: check if splunk is installed on linux systems and the process name</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705070#M20907</link>
      <description>&lt;P&gt;would windows systems also listen or show connected on these ports?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;port 9997 or 9998&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 16:58:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705070#M20907</guid>
      <dc:creator>LinkLoop</dc:creator>
      <dc:date>2024-11-22T16:58:46Z</dc:date>
    </item>
    <item>
      <title>Re: check if splunk is installed on linux systems and the process name</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705073#M20908</link>
      <description>&lt;P&gt;They should.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 17:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/705073#M20908</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-11-22T17:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: check if splunk is installed on linux systems and the process name</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/708922#M21322</link>
      <description>&lt;P&gt;so if its forwarding, there should be a splunkd.log that is recent?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 18:39:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/708922#M21322</guid>
      <dc:creator>LinkLoop</dc:creator>
      <dc:date>2025-01-15T18:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: check if splunk is installed on linux systems and the process name</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/708954#M21330</link>
      <description>&lt;P&gt;Not exactly. If splunkd is running then it generates events into splunkd.log, but it’s not 100% indicator that it is forwarding also. But you could look events from that file which told this. Those are “connected/forwarding server 1.2.3.4:9997” or something similar (I cannot check correct lines now).&lt;/P&gt;&lt;P&gt;Is it possible that you look that information from server side? Just search those from _internal logs or even from MC?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 07:13:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/708954#M21330</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-16T07:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: check if splunk is installed on linux systems and the process name</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/708990#M21337</link>
      <description>&lt;P&gt;i checked splunkd.log but did not find anything listed under connected or 9997&lt;/P&gt;&lt;P&gt;i did a netstat -an and cannot find any connections to 9997.&lt;/P&gt;&lt;P&gt;where else can i check on a windows system that logs are forwarding?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 14:57:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/check-if-splunk-is-installed-on-linux-systems-and-the-process/m-p/708990#M21337</guid>
      <dc:creator>LinkLoop</dc:creator>
      <dc:date>2025-01-16T14:57:45Z</dc:date>
    </item>
  </channel>
</rss>

