Getting Data In

How to install Splunk forwarders on AWS EC2 instances?


I have Splunk Enterprise on an AWS EC2 Server, and need to install forwarders on two other EC2 Instances. Can someone direct me to documentation on how to do this? Not finding this case in the documentation. Thanks!


Use ansible or some other deployment tool to load the binaries and configs
Use a deployment tool for the binaries, and Forwarder Manager to manage configs
Bake Splunk into a custom AMI and do a bit of post-config if you want, using the tool of choice

0 Karma

Splunk Employee
Splunk Employee
  1. Download appropriate binaries
  2. upload to EC2 instances
  3. Follow installation instructions to install the forwarder. It's no different than installing it on-prem.

And, in case you haven't seen this TechBrief yet, some overview information.