<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: setup splunk/forwader in the same platform in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/695979#M115524</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, it's possible, but you should define the purpose, the borders and the Use Cases of your lab.&lt;/P&gt;&lt;P&gt;In other words: what architecture you need to test: a distributed environment? only forwarder and Indexer? what else?&lt;/P&gt;&lt;P&gt;In my lab I have seved virtual machines with&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;two Indexers,&lt;/LI&gt;&lt;LI&gt;three Search Heads,&lt;/LI&gt;&lt;LI&gt;a Management Node (Cluster Manager, Deployer, License Master, Monitoring Console and Deployment Server),&lt;/LI&gt;&lt;LI&gt;one Universal Forwarder.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I did it on pc pc that hase 16 vCPUs and 32 GB TAM).&lt;/P&gt;&lt;P&gt;As I said, you can do this, it depends on your requirements and the resources you have.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Mon, 12 Aug 2024 10:44:07 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-08-12T10:44:07Z</dc:date>
    <item>
      <title>setup splunk/forwader in the same platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/695977#M115523</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I want to setup a home lab like splunk Enterprise and splunk forwarder on the same os to pull the logs into splunk. Is it possible to setup in this way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 10:28:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/695977#M115523</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2024-08-12T10:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: setup splunk/forwader in the same platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/695979#M115524</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, it's possible, but you should define the purpose, the borders and the Use Cases of your lab.&lt;/P&gt;&lt;P&gt;In other words: what architecture you need to test: a distributed environment? only forwarder and Indexer? what else?&lt;/P&gt;&lt;P&gt;In my lab I have seved virtual machines with&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;two Indexers,&lt;/LI&gt;&lt;LI&gt;three Search Heads,&lt;/LI&gt;&lt;LI&gt;a Management Node (Cluster Manager, Deployer, License Master, Monitoring Console and Deployment Server),&lt;/LI&gt;&lt;LI&gt;one Universal Forwarder.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I did it on pc pc that hase 16 vCPUs and 32 GB TAM).&lt;/P&gt;&lt;P&gt;As I said, you can do this, it depends on your requirements and the resources you have.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 10:44:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/695979#M115524</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-12T10:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: setup splunk/forwader in the same platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/695985#M115527</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;I am looking for&amp;nbsp;&lt;SPAN&gt;only forwarder and Indexer.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 12:04:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/695985#M115527</guid>
      <dc:creator>smith_</dc:creator>
      <dc:date>2024-08-12T12:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: setup splunk/forwader in the same platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/696024#M115534</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/252275"&gt;@smith_&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in this case, you have to configure two virtual machines that are connected:&lt;/P&gt;&lt;P&gt;one with Splunk Enterprise and one with Splunk Universal Forwarder.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 15:29:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/696024#M115534</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-12T15:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: setup splunk/forwader in the same platform</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/696030#M115536</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;the easiest way is use separate virtual machines, but you could do it also e.g. on linux box on lab env. In production this is not proposed way to do it.&lt;/P&gt;&lt;P&gt;In linux you can just install 1st indexers and start it. Then you could install UF and start it with different ports for mgmt and probably some other. You just must check correct parameters from docs (I cannot find those now). But if I recall right UF tell that normal ports are reserved and ask to use some other ports.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 15:46:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/setup-splunk-forwader-in-the-same-platform/m-p/696030#M115536</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2024-08-12T15:46:53Z</dc:date>
    </item>
  </channel>
</rss>

