Deployment Architecture

How to forward data logs from Linux to Splunk?

Dijanad
New Member

We recently purchased the managed splunk cloud instance, I am in the process of adding data. We would like to index our db2diag logs which are sitting on the Linux servers. I went though the process of installing the forwarder and forwarder credentials. Now I am at a loss on how to tell the forwarder what logs to forward to splunk? With the managed splunk cloud instance, you can't do it through the Add Data button. I do have the monitoring console app, and I see the new Linux forwarder there. But I don't see an option there to manipulate the forwarder in any way. Do I have to configure the forwarder inputs on the Linux server?

Also when I look at the monitoring console app, I see the universal forwarder and the heavy forwarder there. But we only installed universal. Is that am installation default?

0 Karma

Dijanad
New Member

So we have splunk cloud. So that seems to work different. What I see is that you have to use splunk web to configure forwarders for the cloud version. Is that correct?

0 Karma

Dijanad
New Member

The inputs.conf That has to be written on the unix server. There isn't a gui to manage forwarders?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...