Hello Everyone,
I have installed app Splunk for Windows Infrastructure.
I am going to set up around 200 Windows servers in Splunk for Infra monitoring.
How many forwarders are required for 200 Windows servers?
Thanks
Sonia
Short answer: 200
Install 1 universal forwarder on every host you want to monitor.
You can also monitor Windows servers remotely using WMI or Event Log Forwarding but it won't be as reliable and flexible as having your dedicated UF running locally.
Hope that helps.
Thanks,
J
Short answer: 200
Install 1 universal forwarder on every host you want to monitor.
You can also monitor Windows servers remotely using WMI or Event Log Forwarding but it won't be as reliable and flexible as having your dedicated UF running locally.
Hope that helps.
Thanks,
J
Thanks for your reply J !!!!
How universal forwarder works?
Which port number it uses?
Is this similar to agent in other monitoring tool?
Suppose, If Universal forwarder is stooped working, then will it stop sending data to Indexer?
Thanks
Sonia
Hi,
Yes all your points are correct. The UF is just a lightweight agent that collects data.
It is a different installer. Take a look at the docs:
http://www.splunk.com/en_us/download/universal-forwarder.html
http://docs.splunk.com/Splexicon:Universalforwarder
http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Universalforwarderdeploymentoverview
http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Aboutforwardingandreceivingdata
https://answers.splunk.com/answers/58888/what-are-the-ports-that-i-need-to-open.html
Hope that helps.
Thanks,
J