Getting Data In

How to install splunk app for linux without installing the universal forwarder?

sabaKhadivi
Path Finder

Can I use splunk app for linux without installing universal forwarder on each linux host I need their logs?

0 Karma

pgelnar_hci
New Member

you can use forwarding from syslog (rsyslog, syslogng etc) or as named above. i prefer fluentbit

0 Karma

woodcock
Esteemed Legend

The app is useless without the logs but certainly there are may ways to get them in. You can use the UF, snare, fluentd, to name just a few tools.

0 Karma

gjanders
SplunkTrust
SplunkTrust

If you are referring to Splunk Add-on for Linux then you could read the documentation around this for example configure collectd to send data

If you are using collectd on the remote machines you would not need a universal forwarder on each Linux machine.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...