Getting Data In

Can you give me some clarification on Monitoring _internal logs?

Explorer

Hi Everyone,

I am new to Splunk. Here I am having some clarification on monitoring _internal logs.

I do have 4 IDX, 2 SHD, DPL, DPM, Master. Am I able to monitor the logs from those instances without using a universal forwarder (UF)?

We could use the UF to forward logs, but Splunk advises us to use one instance in one server.

Please Advice!

0 Karma
1 Solution

SplunkTrust
SplunkTrust

All of your Splunk instances (except the indexers) should be forwarding their internal logs to your indexers. They have the ability to forward logs without a separate forwarder. See https://docs.splunk.com/Documentation/Splunk/7.2.3/DistSearch/Forwardsearchheaddata

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

SplunkTrust
SplunkTrust

All of your Splunk instances (except the indexers) should be forwarding their internal logs to your indexers. They have the ability to forward logs without a separate forwarder. See https://docs.splunk.com/Documentation/Splunk/7.2.3/DistSearch/Forwardsearchheaddata

---
If this reply helps you, an upvote would be appreciated.

View solution in original post

0 Karma

Explorer

Thank you Mr.Richgalloway

Did those instances forward the OS logs without UF?

0 Karma

SplunkTrust
SplunkTrust

Yes, they do, if you follow the instructions in the link.

---
If this reply helps you, an upvote would be appreciated.
0 Karma