Deployment Architecture

Want to analyse all linux connected system logs on real time basis so please tell me the configuration of using forwarder.

kunalagarwal
New Member

Linux basis Configuration

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

You'll want to install the Universal forwarder on each linux server. Then set up a monitor for the log files (/var/log/ folder) and forward to the indexer. On the indexer you'll need to enable receiving in the manager. See our docs below.

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Aboutforwardingandreceivingdata http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...