All Apps and Add-ons

Splunk App for Unix and Linux free version

nniehoff
New Member

I am trying out the free license of splunk. Sorry I'm still a splunk noob so maybe I don't know what I'm doing. I'm trying to get the Splunk App for Unix and Linux to collect data from several ubuntu hosts. I've installed the splunk server, installed the universal forwarder on the remote system, added the forward-server, install the splunk app for unix and linux on the splunk server but I still don't see any hosts listed in the app or any data coming in. From what I can tell I need to some things with the Splunk Add-on for Unix and Linux to complete the configuration. My problem is the Splunk Add-on for Unix and Linux doesn't appear to work with the free license. Am I missing some thing or am I just not going to be able to do this with the free license? Thanks,
Nick

0 Karma

ChrisG
Splunk Employee
Splunk Employee

Yes, you can use the universal forwarder with the free version. See the Free vs. Enterprise comparison page.

Are you following the installation instructions in the documentation? Just want to make sure you have the right bits installed in the right locations in your deployment. If you're sure you do, then there might be troubleshooting steps to take with your configuration. But first things first.

0 Karma

nniehoff
New Member

Actually I've managed to get the universal forwarder working with some other apps, but I am more interested in the "Splunk App for Unix and Linux". What Data Inputs do I need to setup on the server and on the forwarder side for this app to get any data? The other app I'm curious about is the "Splunk Add-on for Unix and Linux" which seems to have a lot of data inputs already set up on the server which seem like they would be cool for my forwarders to forward like cpu.sh etc but this app seems like it's not free, is this the case?

0 Karma

jeremiahc4
Builder

It's been a while since I played with the free version (v. 4.2.2?), but as of that time it was my understanding that the free version would not receive data from forwarders.

I tried looking it up*, but the wording is vague... ~"Splunk free can be used as a forwarder but cannot be a client to a deployment server"

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...