<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: If I currently have a single Windows server running Splunk, how can I add a new Linux front end server to use apps that require Linux? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/If-I-currently-have-a-single-Windows-server-running-Splunk-how/m-p/200271#M39583</link>
    <description>&lt;P&gt;Setup the Linux server as a forwarder, and configure the outputs to point to the Windows Splunk instance. &lt;/P&gt;

&lt;P&gt;Output.conf on Linux Splunk instance:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:windows_indexer]
server=&amp;lt;windows_host/IP&amp;gt;:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also configure the Windows Splunk instance with a Splunk TCP input:&lt;BR /&gt;
Inputs.conf on Windows Splunk index:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunktcp://9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Don't forget about firewall on the Windows host, and also any indexes required for apps on the Linux instance will need to be installed on the Windows. Basically, TAs go on Linux, app goes on Windows (if you don't plan on using the Linux front end).&lt;/P&gt;</description>
    <pubDate>Mon, 26 Oct 2015 19:06:21 GMT</pubDate>
    <dc:creator>stmyers7941</dc:creator>
    <dc:date>2015-10-26T19:06:21Z</dc:date>
    <item>
      <title>If I currently have a single Windows server running Splunk, how can I add a new Linux front end server to use apps that require Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-currently-have-a-single-Windows-server-running-Splunk-how/m-p/200270#M39582</link>
      <description>&lt;P&gt;Right now I have Splunk set up on a single Windows server, but have found some apps that require a Linux server to run the apps.  I would like to add a Linux front end server to use the Linux apps and keep the Windows server for the apps that require a Windows sever to run from, and keep the indexer there as well for now.  I am having trouble finding in the documentation how to set up this configuration.  I would assume this would be possible and still have only one site and single pane of glass for my users as well?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 18:22:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-currently-have-a-single-Windows-server-running-Splunk-how/m-p/200270#M39582</guid>
      <dc:creator>erickopp</dc:creator>
      <dc:date>2015-10-26T18:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: If I currently have a single Windows server running Splunk, how can I add a new Linux front end server to use apps that require Linux?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/If-I-currently-have-a-single-Windows-server-running-Splunk-how/m-p/200271#M39583</link>
      <description>&lt;P&gt;Setup the Linux server as a forwarder, and configure the outputs to point to the Windows Splunk instance. &lt;/P&gt;

&lt;P&gt;Output.conf on Linux Splunk instance:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:windows_indexer]
server=&amp;lt;windows_host/IP&amp;gt;:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also configure the Windows Splunk instance with a Splunk TCP input:&lt;BR /&gt;
Inputs.conf on Windows Splunk index:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunktcp://9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Don't forget about firewall on the Windows host, and also any indexes required for apps on the Linux instance will need to be installed on the Windows. Basically, TAs go on Linux, app goes on Windows (if you don't plan on using the Linux front end).&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 19:06:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/If-I-currently-have-a-single-Windows-server-running-Splunk-how/m-p/200271#M39583</guid>
      <dc:creator>stmyers7941</dc:creator>
      <dc:date>2015-10-26T19:06:21Z</dc:date>
    </item>
  </channel>
</rss>

