These are the normal steps for a single-instance Splunk installation. Different procedures apply to distributed and clustered installations. These should be familiar to you from your Splunk admin classes.
1. Download the app to your workstation and uncompress it. Save the compressed file.
2. Review the README file and any other documentation for installation instructions.
3. Review the indexes.conf file for any indexes you need to add to your indexers. Add them to your local index configuration and disable them in the app.
4. Review the remaining .conf files to ensure the settings are suitable for your Splunk environment.
5. Sign in to Splunk as an admin and go to the Apps management page.
6. Click on the "Install app from file" button and select the downloaded (compressed) app file. Click Upload.
7. Wait for the installation to complete and allow Splunk to restart, if necessary.
Like I said, those are the normal steps. You will not be following them because the app is not intended for your version of Splunk and may work or may fail in unknown ways. You should follow steps 1-4 with the goal of understanding how the app works and how you can use that knowledge to create your own app. Keep in mind the app may not work at all with your version of weblogic.
Installed splunk 7.2 Forwarder in the linux server, Same server we have installed weblogic server (12c) and created domain as well.Here we are trying to achieve this weblogic applications to integrate with splunk app.
Splunk Home: /oracle/Splunk/splunk
Weblogic Home: /oracle/app/Middleware/wlserver
1) Deployed add-on file "oracle-weblogic-app-for-splunk10-beta2.tgz" in the splunk application.
2) Deployed Sideview utils file "sideviewutils.tar" in the splunk application.
3) Updated the required weblogic & admin server details in inputs.conf and setWlstEnv.sh, as per the TA installation document. Later we placed the files in the below stated location
E.g.: Below lines are modified in the inputs.conf file in our environment, did same for EVERY HOUR & # EVERY DAY
[script://./bin/runWlstScriptsMinute.sh /oracle/Splunk/splunk/etc/deployment-apps/Function1WebLogicServerTA /oracle/app/Middleware/wlserver10.3]
disabled = false
index = wls
sourcetype = wlstrash
interval = 300
E.g.: Below lines are modified in the setWlstEnv.sh in our environment
Both files are updated as per the TA document "Splunk for Oracle Weblogic Server (v.1.0.1Beta)".
Then moving forward to step 6, documents says that "Once you have completed these configurations, deploy the TA to the forwarder residing on the WLS Admin Server by either Using the Splunk deployment server or copying the TA to the forwarder manually."
Please advise me regarding this deployment, am not clear in this step. Currently I have kept this config file folder "Function1WebLogicServerTA" under "$SPLUNK_HOME/etc/apps". We need to deploy on Indexer server Please let me know where & how to deploy this files.
Still am not receiving the data .