Getting Data In

Can you give me some clarification on Monitoring _internal logs?

EHariharan
Explorer

Hi Everyone,

I am new to Splunk. Here I am having some clarification on monitoring _internal logs.

I do have 4 IDX, 2 SHD, DPL, DPM, Master. Am I able to monitor the logs from those instances without using a universal forwarder (UF)?

We could use the UF to forward logs, but Splunk advises us to use one instance in one server.

Please Advice!

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

All of your Splunk instances (except the indexers) should be forwarding their internal logs to your indexers. They have the ability to forward logs without a separate forwarder. See https://docs.splunk.com/Documentation/Splunk/7.2.3/DistSearch/Forwardsearchheaddata

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

All of your Splunk instances (except the indexers) should be forwarding their internal logs to your indexers. They have the ability to forward logs without a separate forwarder. See https://docs.splunk.com/Documentation/Splunk/7.2.3/DistSearch/Forwardsearchheaddata

---
If this reply helps you, Karma would be appreciated.
0 Karma

EHariharan
Explorer

Thank you Mr.Richgalloway

Did those instances forward the OS logs without UF?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, they do, if you follow the instructions in the link.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...