Deployment Architecture

How to forward data logs from Linux to Splunk?

Dijanad
New Member

We recently purchased the managed splunk cloud instance, I am in the process of adding data. We would like to index our db2diag logs which are sitting on the Linux servers. I went though the process of installing the forwarder and forwarder credentials. Now I am at a loss on how to tell the forwarder what logs to forward to splunk? With the managed splunk cloud instance, you can't do it through the Add Data button. I do have the monitoring console app, and I see the new Linux forwarder there. But I don't see an option there to manipulate the forwarder in any way. Do I have to configure the forwarder inputs on the Linux server?

Also when I look at the monitoring console app, I see the universal forwarder and the heavy forwarder there. But we only installed universal. Is that am installation default?

0 Karma

Dijanad
New Member

So we have splunk cloud. So that seems to work different. What I see is that you have to use splunk web to configure forwarders for the cloud version. Is that correct?

0 Karma

Dijanad
New Member

The inputs.conf That has to be written on the unix server. There isn't a gui to manage forwarders?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...