Getting Data In

How to install splunk app for linux without installing the universal forwarder?

sabaKhadivi
Path Finder

Can I use splunk app for linux without installing universal forwarder on each linux host I need their logs?

0 Karma

pgelnar_hci
New Member

you can use forwarding from syslog (rsyslog, syslogng etc) or as named above. i prefer fluentbit

0 Karma

woodcock
Esteemed Legend

The app is useless without the logs but certainly there are may ways to get them in. You can use the UF, snare, fluentd, to name just a few tools.

0 Karma

gjanders
SplunkTrust
SplunkTrust

If you are referring to Splunk Add-on for Linux then you could read the documentation around this for example configure collectd to send data

If you are using collectd on the remote machines you would not need a universal forwarder on each Linux machine.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...