Getting Data In

How to configure forwarding on an amazone EC2 server linux ?

fdi01
Motivator

Hey,

We run Splunk enterprise on Amazon AMI Linux.

I want to configure the Splunk forwarder from my amazone EC2 server.

is it possible?

thanks a lot!

nkwong_splunk
Splunk Employee
Splunk Employee

Yes, you can run the Splunk Universal Forwarder on Amazon EC2 instances. The Splunk Universal Forwarder is available for multiple operating systems such as Linux, Windows, FreeBSD, etc. You will also need to configure the EC2 Security Group to allow the Splunk Indexer to receive data from the Splunk Forwarder on either the default port of TCP 9997 or another user defined TCP port.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...