Getting Data In

How to add hosts to splunk server

wanted819
Engager

Hi,

I have installed splunk in centos and it is working fine.
And i have installed the universal forwarder in another host(centos).
Now i have no idea, "how to add the client host to splunk server?"

Regards,
karthi

Tags (2)
0 Karma
1 Solution

kristian_kolb
Ultra Champion

The short answer is

On the main splunk installation (call it Indexer/Search Interface/Splunk Web); go into Manager, go into "Forwarding and Receiving", click "Enable Receiving", fill in a port number, e.g. 9997.

On the Forwarder, it's probably easiest if you simply

  • su splunk
  • /opt/splunk/bin/splunk add forward-server <IP:port>

That sets up the connection between the two hosts.

But I suggest you read up on the docs, there is a 'tutorial' section that will cover the basics, and a 'distributed deployment' section that will cover forwarding. There is also a 'getting data in' section with detailed 'recipies' for various scenarios.

http://docs.splunk.com/Documentation/Splunk/latest/Tutorial/WelcometotheSplunkTutorial

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview

http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor

Hope this helps,

K

View solution in original post

kristian_kolb
Ultra Champion

The short answer is

On the main splunk installation (call it Indexer/Search Interface/Splunk Web); go into Manager, go into "Forwarding and Receiving", click "Enable Receiving", fill in a port number, e.g. 9997.

On the Forwarder, it's probably easiest if you simply

  • su splunk
  • /opt/splunk/bin/splunk add forward-server <IP:port>

That sets up the connection between the two hosts.

But I suggest you read up on the docs, there is a 'tutorial' section that will cover the basics, and a 'distributed deployment' section that will cover forwarding. There is also a 'getting data in' section with detailed 'recipies' for various scenarios.

http://docs.splunk.com/Documentation/Splunk/latest/Tutorial/WelcometotheSplunkTutorial

http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview

http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor

Hope this helps,

K

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...