<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: whether Splunk Light and Splunk universal forwarder cannot be installed in same machine? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269357#M503</link>
    <description>&lt;P&gt;Hi again,&lt;/P&gt;

&lt;P&gt;I think you might benefit from reading through some of our documentation on forwarding data.&lt;/P&gt;

&lt;P&gt;You should only have one instance of Splunk Light and then one or more Universal Forwarders running on one or more remote machines where the log files are to be monitored.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/Forwarderdeploymenttopologies"&gt;http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/Forwarderdeploymenttopologies&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In the diagram in the link above your Splunk Light instance is labelled the Indexer.&lt;/P&gt;

&lt;P&gt;You should also read this section of our documentation:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/HowtoforwarddatatoSplunkLight"&gt;http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/HowtoforwarddatatoSplunkLight&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can forward log data from Windows or Linux systems using the Universal Forwarder and your Splunk Light instance can run on either Linux or Windows.&lt;/P&gt;

&lt;P&gt;I hope this helps.&lt;/P&gt;

&lt;P&gt;Cheers, Greg.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2016 11:34:57 GMT</pubDate>
    <dc:creator>gwiley_splunk</dc:creator>
    <dc:date>2016-04-05T11:34:57Z</dc:date>
    <item>
      <title>whether Splunk Light and Splunk universal forwarder cannot be installed in same machine?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269350#M496</link>
      <description>&lt;P&gt;I have installed Splunk light in my local machine. I just want to get the logs from other remote machines.&lt;/P&gt;

&lt;P&gt;I have read it like we can done it by Splunk Universal forwarder.i have tried to install splunk universal forwarder in the same machine. after that splunk light web portal stopped working.&lt;/P&gt;

&lt;P&gt;if you want to get the logs from remote machine, do we need to install universal forwarder in the particular remote machine? &lt;/P&gt;

&lt;P&gt;Kindly clarify on this&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 10:00:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269350#M496</guid>
      <dc:creator>Monica7</dc:creator>
      <dc:date>2016-03-29T10:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: whether Splunk Light and Splunk universal forwarder cannot be installed in same machine?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269351#M497</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;The Universal Forwarder is installed on the remote machines where the logs are. You configure the Universal Forwarders to monitor the log files from which you want to collect events and then to send these events to your Splunk Light instance.&lt;/P&gt;

&lt;P&gt;Check out the &lt;A href="http://docs.splunk.com/Documentation/SplunkLight/latest/GettingStarted/Receivedatafromaforwarder"&gt;documentation&lt;/A&gt; on how to do this for Splunk Light.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 12:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269351#M497</guid>
      <dc:creator>gwiley_splunk</dc:creator>
      <dc:date>2016-03-29T12:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: whether Splunk Light and Splunk universal forwarder cannot be installed in same machine?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269352#M498</link>
      <description>&lt;P&gt;The documentation he refers to is: &lt;A href="http://docs.splunk.com/Documentation/SplunkLight/6.3.3/Installation/InstallanddeployaUF"&gt;Install and deploy a universal forwarder&lt;/A&gt; in the Splunk Light &lt;EM&gt;Installation Manual.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2016 16:10:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269352#M498</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-03-29T16:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: whether Splunk Light and Splunk universal forwarder cannot be installed in same machine?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269353#M499</link>
      <description>&lt;P&gt;Thanks for picking this up Chris; I'd added the link in the editor and it previewed just fine; don't know why it didn't show up in the final submission:( Lesson learned today - always check the final submission!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 08:12:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269353#M499</guid>
      <dc:creator>gwiley_splunk</dc:creator>
      <dc:date>2016-03-30T08:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: whether Splunk Light and Splunk universal forwarder cannot be installed in same machine?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269354#M500</link>
      <description>&lt;P&gt;I think you can install on the same machine. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 09:16:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269354#M500</guid>
      <dc:creator>samj3341</dc:creator>
      <dc:date>2016-03-30T09:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: whether Splunk Light and Splunk universal forwarder cannot be installed in same machine?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269355#M501</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Yes you can install the Universal Forwarder on the same machine as the Splunk Light instance though there wouldn't necessarily be any reason to do so since you can have the Splunk Light instance monitor local log files or receive syslog (or other network inputs) input directly. However, the OPs suggests that the log files are on remote machines so in this case you'd want the Universal Forwarder on those remote machines.&lt;/P&gt;

&lt;P&gt;Cheers, Greg.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 10:15:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269355#M501</guid>
      <dc:creator>gwiley_splunk</dc:creator>
      <dc:date>2016-03-30T10:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: whether Splunk Light and Splunk universal forwarder cannot be installed in same machine?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269356#M502</link>
      <description>&lt;P&gt;Hi Greg,&lt;/P&gt;

&lt;P&gt;Thanks for your answer. I have installed splunk light in one of the Linux server(which is accessible from local machine) and in my local machine also.&lt;/P&gt;

&lt;P&gt;I am going to install universal forwarder in remote desktop server in windows. Whether I need to install forwarder in Linux box also(in remote desktop server). Or just installing and configuring in windows alone is enough for forwarding the logs to splunk light instance?&lt;/P&gt;

&lt;P&gt;I am beginner in this splunk concept. so kindly clarify on this. thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 13:15:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269356#M502</guid>
      <dc:creator>Monica7</dc:creator>
      <dc:date>2016-04-04T13:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: whether Splunk Light and Splunk universal forwarder cannot be installed in same machine?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269357#M503</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;

&lt;P&gt;I think you might benefit from reading through some of our documentation on forwarding data.&lt;/P&gt;

&lt;P&gt;You should only have one instance of Splunk Light and then one or more Universal Forwarders running on one or more remote machines where the log files are to be monitored.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/Forwarderdeploymenttopologies"&gt;http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/Forwarderdeploymenttopologies&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In the diagram in the link above your Splunk Light instance is labelled the Indexer.&lt;/P&gt;

&lt;P&gt;You should also read this section of our documentation:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/HowtoforwarddatatoSplunkLight"&gt;http://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/HowtoforwarddatatoSplunkLight&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can forward log data from Windows or Linux systems using the Universal Forwarder and your Splunk Light instance can run on either Linux or Windows.&lt;/P&gt;

&lt;P&gt;I hope this helps.&lt;/P&gt;

&lt;P&gt;Cheers, Greg.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 11:34:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/whether-Splunk-Light-and-Splunk-universal-forwarder-cannot-be/m-p/269357#M503</guid>
      <dc:creator>gwiley_splunk</dc:creator>
      <dc:date>2016-04-05T11:34:57Z</dc:date>
    </item>
  </channel>
</rss>

