All Apps and Add-ons

Is there a *nix app for a UF when using a Windows Indexer?

kmsnyde
Explorer

I am using a Splunk Windows Indexer with both Windows and *nix workstations. I will employ the use of the Splunk App for Windows and the Windows TA add-on for the Windows Universal Forwarders to enhance my data collection/display. Can the *nix TA add-on for *nix Universal Forwarders be used to send data to the Splunk App for Windows? If not, what can I use for the *nix Universal Forwarders in a similar fashion as the Windows TA?

dwaddle
SplunkTrust
SplunkTrust

The *nix TA app can be used in conjunction with the *nix app, just like the Windows TA can be used with the Windows app. In both cases, the 'main app' is platform independent. That is, it does not care if your indexers and search heads are running on Windows or Unix. Only the respective TA app (which is doing the data collection) is picky about platform compatibility at installation.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Well, yes and no. The *nix TA only "works with" the *nix app. That is, the *nix TA creates sources / sourcetypes that the dashboards in the Windows app simply won't understand. But, nothing keeps you from using the *nix app on your Windows indexers.

0 Karma

kmsnyde
Explorer

Just so I'm clear, the *nix TA app on the *nix Universal Forwarder "can" work with the Splunk App for Windows on my Indexer? Thanks.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...