<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Do we need to install Splunk Light in both Windows and Linux to forward data from remote hosts? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Do-we-need-to-install-Splunk-Light-in-both-Windows-and-Linux-to/m-p/280344#M53646</link>
    <description>&lt;P&gt;See the topics in the Getting Data In chapter of the Splunk Light &lt;EM&gt;User Guide&lt;/EM&gt;. The topic &lt;A href="http://docs.splunk.com/Documentation/SplunkLight/6.4.0/GettingStarted/Aboutaddingdata"&gt;About adding data to Splunk Light&lt;/A&gt; is a good starting point with links to more specific procedures. &lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2016 17:03:17 GMT</pubDate>
    <dc:creator>andrewb_splunk</dc:creator>
    <dc:date>2016-04-11T17:03:17Z</dc:date>
    <item>
      <title>Do we need to install Splunk Light in both Windows and Linux to forward data from remote hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Do-we-need-to-install-Splunk-Light-in-both-Windows-and-Linux-to/m-p/280343#M53645</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have installed Splunk light in Windows and in Linux server also. I have installed a universal forwarder in the same Linux machine.&lt;/P&gt;

&lt;P&gt;In Splunk Light web page, Data - &amp;gt; Add Data -&amp;gt; receiving -&amp;gt; new. I have added port as 9997&lt;/P&gt;

&lt;P&gt;and in Linux server, &lt;/P&gt;

&lt;P&gt;I have added forward server and deploy server in Splunk universal forwarder with the following commands.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;./splunk add forward-server mysystemip:9997&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;and &lt;CODE&gt;./splunk set deploy-poll mysystemip:8089&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;and started the universal forwarder and Splunk.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[s249635@CTSC00621983301 ~]$ ps -ef|grep splunk
s249635   2994     1  0 13:53 ?        00:00:03 splunkd -p 8089 start
s249635   2995  2994  0 13:53 ?        00:00:00 [splunkd pid=2994] splunkd -p 8089 start [process-runner]
s249635   3054  2995  0 13:53 ?        00:00:05 /home/s249635/splunk/bin/python -O /home/s249635/splunk/lib/python2.7/site-packages/splunk/appserver/mrsparkle/root.py --proxied=127.0.0.1,8065,8000
s249635   3096  2995  0 13:53 ?        00:00:00 /home/s249635/splunk/bin/splunkd instrument-resource-usage -p 8089
s249635   3329     1  0 14:04 ?        00:00:03 splunkd -p 9997 restart
s249635   3330  3329  0 14:04 ?        00:00:00 [splunkd pid=3329] splunkd -p 9997 restart [process-runner]
s249635   3606  3579  0 14:19 pts/0    00:00:00 grep splunk
[s249635@CTSC00621983301 ~]$
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Now both are up and running. In Splunk Web, I have my Linux machine in the available host list in Add data -&amp;gt;forward -&amp;gt; select forwarders.&lt;/P&gt;

&lt;P&gt;I have mentioned the path where logs need to be tracked in Splunk Web.&lt;/P&gt;

&lt;P&gt;Question is whether any other configurations have to be done apart from this in order to forward data from remote hosts/server?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 08:53:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Do-we-need-to-install-Splunk-Light-in-both-Windows-and-Linux-to/m-p/280343#M53645</guid>
      <dc:creator>Monica7</dc:creator>
      <dc:date>2016-04-11T08:53:20Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need to install Splunk Light in both Windows and Linux to forward data from remote hosts?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Do-we-need-to-install-Splunk-Light-in-both-Windows-and-Linux-to/m-p/280344#M53646</link>
      <description>&lt;P&gt;See the topics in the Getting Data In chapter of the Splunk Light &lt;EM&gt;User Guide&lt;/EM&gt;. The topic &lt;A href="http://docs.splunk.com/Documentation/SplunkLight/6.4.0/GettingStarted/Aboutaddingdata"&gt;About adding data to Splunk Light&lt;/A&gt; is a good starting point with links to more specific procedures. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 17:03:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Do-we-need-to-install-Splunk-Light-in-both-Windows-and-Linux-to/m-p/280344#M53646</guid>
      <dc:creator>andrewb_splunk</dc:creator>
      <dc:date>2016-04-11T17:03:17Z</dc:date>
    </item>
  </channel>
</rss>

