All Apps and Add-ons

Splunk Add-on for Apache Web Server: If I have this app do I still need a forwarder to forward Apache logs?

deepakc
Builder

I have Splunk 7.1 / RHEL65 / Test enviroment
(New to splunk)

I see you have Splunk Add-on for Apache Web Server, but do you still need a forwarder to forward the apache logs?

Rgds
Dee

0 Karma
1 Solution

mayurr98
Super Champion

hey @deepakc

Yes, you will still need forwarder to forward apache logs
as add-on works on the top of universal forwarder.add-on extracts the data from source and forwarder forwards data to the indexer.

difference between forwarder and add-on is as follows:

universal forwarder: it is used to send data from source to indexer
Splunk app: you need to install in indexer or search head and shows you report, visualization
Splunk addon: you need to install Splunk add-on in forwarder and addon extract the data from source (example run scripts in UNIX addon) v and send to indexer via forwarder

Let me know if this helps you!

View solution in original post

0 Karma

mayurr98
Super Champion

hey @deepakc

Yes, you will still need forwarder to forward apache logs
as add-on works on the top of universal forwarder.add-on extracts the data from source and forwarder forwards data to the indexer.

difference between forwarder and add-on is as follows:

universal forwarder: it is used to send data from source to indexer
Splunk app: you need to install in indexer or search head and shows you report, visualization
Splunk addon: you need to install Splunk add-on in forwarder and addon extract the data from source (example run scripts in UNIX addon) v and send to indexer via forwarder

Let me know if this helps you!

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...