All Apps and Add-ons

How do I install it in Universal Forwarder?

charleslcso
Explorer

I have machines that has only the Universal Forwarder installed. How to I install and configure Splunk for *nix to run on these machines and forward data to the Indexer?

0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

You can install the app simply by exploding the .tar.gz into $SPLUNK_HOME/etc/apps. To configure it, you will need to update some local config files to enable the various inputs.

The easiest way to configure might be to install an lightweight forwarder with Splunk for *nix, go through the configuration panels there, and then use the updated app with configuration files to deploy to your Universal forwarders.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

You can install the app simply by exploding the .tar.gz into $SPLUNK_HOME/etc/apps. To configure it, you will need to update some local config files to enable the various inputs.

The easiest way to configure might be to install an lightweight forwarder with Splunk for *nix, go through the configuration panels there, and then use the updated app with configuration files to deploy to your Universal forwarders.

charleslcso
Explorer

Do I make a directory copy of $SPLUNK_HOME/etc/apps to the Universal Forwarder's $SPLUNK_HOME/etc/apps?

I am thinking of using and configuring a test machine as you suggested.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...