<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do you get all Splunk cluster servers internal Linux log files indexed? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420966#M15006</link>
    <description>&lt;P&gt;We have a requirement to forward all the log files from /var/log internal linux OS on the Splunk Enterprise cluster to a security app the same as all the other linux servers in the system, this includes the Search Heads, Indexers, Distribution and Master Node. Installing a universal forwarder is apparently not recommended. &lt;/P&gt;

&lt;P&gt;What would be the best way to implement this?&lt;/P&gt;</description>
    <pubDate>Mon, 03 Dec 2018 08:10:05 GMT</pubDate>
    <dc:creator>evets</dc:creator>
    <dc:date>2018-12-03T08:10:05Z</dc:date>
    <item>
      <title>How do you get all Splunk cluster servers internal Linux log files indexed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420966#M15006</link>
      <description>&lt;P&gt;We have a requirement to forward all the log files from /var/log internal linux OS on the Splunk Enterprise cluster to a security app the same as all the other linux servers in the system, this includes the Search Heads, Indexers, Distribution and Master Node. Installing a universal forwarder is apparently not recommended. &lt;/P&gt;

&lt;P&gt;What would be the best way to implement this?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 08:10:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420966#M15006</guid>
      <dc:creator>evets</dc:creator>
      <dc:date>2018-12-03T08:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get all Splunk cluster servers internal Linux log files indexed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420967#M15007</link>
      <description>&lt;P&gt;Hi @evets,&lt;/P&gt;

&lt;P&gt;You can implement same monitoring stanza on Splunk Enterprise servers which you are running on UF to monitor all Linux servers, if you have dedicated app on UF to monitor &lt;CODE&gt;/var/log/&lt;/CODE&gt; then you can implement same app on Splunk Enterprise Server.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 09:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420967#M15007</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-12-03T09:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get all Splunk cluster servers internal Linux log files indexed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420968#M15008</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;why is it not recommended to use Universal Forwarders? &lt;/P&gt;

&lt;P&gt;From my point of view you should use Universal Forwarders. Every instance which already have Splunk installed (SH, Indexers,...) can also act as a forwarder, just add the configuration in the outputs.conf.&lt;/P&gt;

&lt;P&gt;Alternativly, you could use something like syslog, send all data to a syslog server and collect them from there with a Universal Forwarder.&lt;/P&gt;

&lt;P&gt;Greetings&lt;/P&gt;

&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 03 Dec 2018 09:47:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420968#M15008</guid>
      <dc:creator>tom_frotscher</dc:creator>
      <dc:date>2018-12-03T09:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do you get all Splunk cluster servers internal Linux log files indexed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420969#M15009</link>
      <description>&lt;P&gt;Thanks for your swift replies guys, I will see it it can be pushed out via the deployment server.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Dec 2018 00:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-do-you-get-all-Splunk-cluster-servers-internal-Linux-log/m-p/420969#M15009</guid>
      <dc:creator>evets</dc:creator>
      <dc:date>2018-12-04T00:00:17Z</dc:date>
    </item>
  </channel>
</rss>

