Getting Data In

How to install splunk app for linux without installing the universal forwarder?

Path Finder

Can I use splunk app for linux without installing universal forwarder on each linux host I need their logs?

0 Karma

New Member

you can use forwarding from syslog (rsyslog, syslogng etc) or as named above. i prefer fluentbit

0 Karma

Esteemed Legend

The app is useless without the logs but certainly there are may ways to get them in. You can use the UF, snare, fluentd, to name just a few tools.

0 Karma


If you are referring to Splunk Add-on for Linux then you could read the documentation around this for example configure collectd to send data

If you are using collectd on the remote machines you would not need a universal forwarder on each Linux machine.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!