My Splunk Infrastructure is ALL Windows. And every Server/Workstation is windows with the exception of one Server which is Linux. I was able to deploy the universal forwarder to the Linux Server and I have began receiving data at my Splunk Indexer. My question is:
Is there an app similar to the App for Windows Infrastructure with built in dashboards for Linux that I can install on my Indexer/Search head (Which is windows)?
Thanks!
There is the Splunk App for Unix and Linux that gives you insight into the *nix server itself, but this requires the Splunk Add-on for Unix and Linux to be installed on the *nix server.
The add-on/app is operations based, so you can get output from top, logs from /var/log, etc which can be turned on/off at will.