Can i use Splunk enterprises as uinversal forwarder? if yes please send me documentation
Thanks.
You can, but you should not. See here:
https://www.splunk.com/blog/2016/12/12/universal-or-heavy-that-is-the-question.html
Hi @ahmemohs03
Yes, you can use full enterprise version of splunk as a universal forwarder,
This makes you to have the Splunk UI enabled as well on the forwarder,
Please go through these docs.
https://docs.splunk.com/Documentation/Forwarder/7.1.2/Forwarder/Abouttheuniversalforwarder
Thanks
Thanks for the reply.
I had Linux A(Splunk enterprises) Linux B(UF)
Linux B logs need to be forwarder to Linux A (weburl..were splunk enterprises installed http:hostname:8000)
Do i need to installed full enterprise version of splunk as a universal forwarder on Linux B?
No, you just need a universal forwarder on Linux B
Thanks,
Linux A (splunk enterprises) Linux B(UF) already there.
but Linux A (splunk enterprises) as index server..weburl not comingup after UF installation.
i see ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf in splunkd.logs of index server.
as mentioned in this other splunk answer, which was asked by you
https://answers.splunk.com/answers/672909/splunk-weburl-not-coming-up-after-configuring-univ.html#an...
Try to enable ssl communication between forwarder and indexer.
You can go through these docs to enable ssl communication between forwarder and indexer.
http://docs.splunk.com/Documentation/Splunk/7.1.2/Security/ConfigureSplunkforwardingtousesignedcerti...
https://answers.splunk.com/answers/397/how-to-configure-ssl-for-forwarding-and-receiving-data.html
Thanks
Thanks you, will try.
Yes, Splunk enterprise can work as a forwarder except that it becomes a heavy forwarder instead of universal forwarder.
http://docs.splunk.com/Documentation/Splunk/7.1.2/Forwarding/Typesofforwarders