Deployment Architecture

Want to analyse all linux connected system logs on real time basis so please tell me the configuration of using forwarder.

kunalagarwal
New Member

Linux basis Configuration

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

You'll want to install the Universal forwarder on each linux server. Then set up a monitor for the log files (/var/log/ folder) and forward to the indexer. On the indexer you'll need to enable receiving in the manager. See our docs below.

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Aboutforwardingandreceivingdata http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...