I completed installing the latest version of Splunk on two systems where the first is the server, and the second is the client. The former has been configured to receive data on port 9997 while the latter has been set up to forward data on the same port. Both systems use Linux operating systems.
What I am trying to set up between the two is a file integrity monitoring of the client from the server. I had several questions concerning this:
How can I verify the connection between the server and the client?
What app, script or procedure, if there are any available, can I use to accomplish this task?
What file(s) do I create and/or modify to let Splunk know what files and/or directories I want to monitor for unexpected changes?
1 - If you are monitoring anything at all on the forwarder then you should (theoretically) see it immediately as you log on to your indexer on the search dashboard (this is assuming you are sending it to a visible index) . If you know you have data being monitored on the forwarder then try searching on the receiver for host= (make sure you use the forwarder's name)
The only thing that I am confused about is the mention of the localhost. Does that mean the readout is actually from the Splunk server, or is the information actually coming from the Hadron client system?