Deployment Architecture

Want to analyse all linux connected system logs on real time basis so please tell me the configuration of using forwarder.

kunalagarwal
New Member

Linux basis Configuration

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

You'll want to install the Universal forwarder on each linux server. Then set up a monitor for the log files (/var/log/ folder) and forward to the indexer. On the indexer you'll need to enable receiving in the manager. See our docs below.

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Aboutforwardingandreceivingdata http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitorfilesanddirectories

0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 3)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Digital Resilience Assessment Launch | How prepared are you for disruption?

Disruption is inevitable. The question is – how prepared are you to handle it? In today’s fast-moving digital ...

Buttercup Games: Further Dashboarding Techniques (Part 2)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...