Deployment Architecture
Highlighted

How do I get the *nix app on the indexer to include the forwarded *nix data.

New Member

I have the unix machines forwarding *nix recordes. I can use search to view the records.

How do get the *nix application on the indexer to include those records. I all I see is the local *nix records.

Tags (1)
0 Karma
Highlighted

Re: How do I get the *nix app on the indexer to include the forwarded *nix data.

Contributor
Highlighted

Re: How do I get the *nix app on the indexer to include the forwarded *nix data.

New Member

I did spend some time looking through this documentation. I may have misunderstood something.

I am using the lightweight forwarder, is that OK.

0 Karma
Highlighted

Re: How do I get the *nix app on the indexer to include the forwarded *nix data.

Contributor

Yes, it works with a lightweight forwarder!

Check the connection on forwarder:

* grep "Connected to /opt/splunk/var/log/splunk/splunkd.log

Check the connection on the indexer:

* grep "Connection accepted from /opt/splunk/var/log/splunk/splunkd.log
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.