All Apps and Add-ons

Splunk Add-on for Unix and Linux

lmjoin
Explorer

Hello , we have indexer clustering setup. We need to implement Splunk Add-on for Unix and Linux to monitors hosts. How we can do.
in this case.

0 Karma

lmjoin
Explorer

we need to install add on on which from we need data and , on indexer and search head we need app.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

See the general instructions to Install an add-on in a distributed environment in the Splunk Add-ons manual. There is also some additional information in Deploy the Splunk Add-on for Unix and Linux in a distributed environment in Deploy and Use the Splunk Add-on for Unix and Linux.

0 Karma

lmjoin
Explorer

Thanks for reply , i have read this and confusion in mind , here need data from hosts only , not from indexer and search head , but in that case i have to install app on both indexer and search head ?. can it have some logic ?

0 Karma

ChrisG
Splunk Employee
Splunk Employee

I am not sure I understand your question. If you don't understand the basic tiers of a Splunk deployment and what the function of each of them is (forwarder, indexer, search head), then you should learn that before you try to install an add-on, especially in a distributed deployment.

You have to install the add-on onto your indexers that are receiving data from your Linux hosts.

You have to install the add-on onto your search heads so you can search the indexed data.

You have to install a universal forwarder and the add-on onto each of your Linux hosts, so they can send the data to the indexer.

0 Karma

lmjoin
Explorer

Thanks
i have put app under master indexer and push and updated and install on SH , add on forwarder but while configuring it require remote server URL , is it for master or any one

0 Karma

lmjoin
Explorer

we need to install on which from we need data add on and on indexer and search head we need app.

0 Karma

sloshburch
Ultra Champion

I'm also having trouble following the question here. Specifically, I can't imagine where "remote server URL" came into play. If you can be super specific and show us what step of what page in the instructions you are running into a challenge then I'm sure we can help.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...