Getting Data In

How to install splunk app for linux without installing the universal forwarder?

sabaKhadivi
Path Finder

Can I use splunk app for linux without installing universal forwarder on each linux host I need their logs?

0 Karma

pgelnar_hci
New Member

you can use forwarding from syslog (rsyslog, syslogng etc) or as named above. i prefer fluentbit

0 Karma

woodcock
Esteemed Legend

The app is useless without the logs but certainly there are may ways to get them in. You can use the UF, snare, fluentd, to name just a few tools.

0 Karma

gjanders
SplunkTrust
SplunkTrust

If you are referring to Splunk Add-on for Linux then you could read the documentation around this for example configure collectd to send data

If you are using collectd on the remote machines you would not need a universal forwarder on each Linux machine.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...