All Apps and Add-ons

Splunk setup with light forwarders and *nix App

bmorgenthaler
Path Finder

So I'm new to Splunk but loving it so far. My question is on system design/layout. I have the following systems:

FSM: Splunk Host (linux)
Mother: DNS/DHCP (linux)
Bastion: ssh/stunnel (linux)

Currently I have setup splunk listeners on 514 udp/tcp and have the syslogs of Mother & Bastion forwarding to it.

I'm interested in the light forwarders and the *nix App, from what I'm reading what would I install the light forwarders on Mother & Bastion along with *nix App to index /etc, /var/log, etc. and then have it all sent to FSM where I also would install the *nix App?

The same question goes for the Linux DNS and DHCP Apps, those would need to go on the server itself and not the Splunk system correct?

Side Question: Anyone have experience getting Sonicwalls to play nice with Splunk?

Thanks.

1 Solution

araitz
Splunk Employee
Splunk Employee

I would recommend that you install the Splunk for Unix and Linux technology add-on on Mother and Bastion, enable the inputs you want to gather, then set both hosts to forward their data to FSM. On FSM, you can install the Splunk for Unix and Linux app and configure Splunk to receive data from Mother and Bastion.

See this page in our docs for forwarding and receiving:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Setupforwardingandreceiving

Regarding Sonicwall, I wrote some field extractions a long time ago, they might be adaptable to 4.x but it has been a while so not sure:

http://splunkbase.splunk.com/apps/Fields/3.x/Technologies/app:Sonicwall+Firewall

Also, see this answer from Dwaddle:

http://splunk-base.splunk.com/answers/2390/sonicwall-4060-logs

View solution in original post

0 Karma

araitz
Splunk Employee
Splunk Employee

I would recommend that you install the Splunk for Unix and Linux technology add-on on Mother and Bastion, enable the inputs you want to gather, then set both hosts to forward their data to FSM. On FSM, you can install the Splunk for Unix and Linux app and configure Splunk to receive data from Mother and Bastion.

See this page in our docs for forwarding and receiving:

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Setupforwardingandreceiving

Regarding Sonicwall, I wrote some field extractions a long time ago, they might be adaptable to 4.x but it has been a while so not sure:

http://splunkbase.splunk.com/apps/Fields/3.x/Technologies/app:Sonicwall+Firewall

Also, see this answer from Dwaddle:

http://splunk-base.splunk.com/answers/2390/sonicwall-4060-logs

0 Karma

bmorgenthaler
Path Finder

Thanks for info araitz, that is what I figured I needed to do, now to get that setup.

As for the sonicwall I have it setup and logging to splunk over syslog and I did see your post about field extractions on it for 3.x. I'll see if I can get it updated to 4.x and post back about it.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...