Getting Data In

How to install splunk app for linux without installing the universal forwarder?

sabaKhadivi
Path Finder

Can I use splunk app for linux without installing universal forwarder on each linux host I need their logs?

0 Karma

pgelnar_hci
New Member

you can use forwarding from syslog (rsyslog, syslogng etc) or as named above. i prefer fluentbit

0 Karma

woodcock
Esteemed Legend

The app is useless without the logs but certainly there are may ways to get them in. You can use the UF, snare, fluentd, to name just a few tools.

0 Karma

gjanders
SplunkTrust
SplunkTrust

If you are referring to Splunk Add-on for Linux then you could read the documentation around this for example configure collectd to send data

If you are using collectd on the remote machines you would not need a universal forwarder on each Linux machine.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...