Getting Data In

Splunk on RPI

DanRyder
New Member

Hi there,

I have been looking into using the RaspberryPI (RPI) and splunk coupled with a SPAM port to monitor network traffic.

Now, I know there is only Stream and the Universal forwarder that are ported for ARM architecture.

Does this mean I have to have Splunk light/ indexer on a seperate machine - Can I get what I need out of using just the forwarder and the Stream app, or do I need the Splunk Light base too?

I've tried the documentation, my understanding is that I would have to have Splunk on a seperate machine, with RPI forwarding information to it. Is the Stream app not standalone? I would rather everything I need on the RPI alone without the need for a second machine.

Many thanks for any clarification you can provide!

0 Karma

dcavuto_splunk
Splunk Employee
Splunk Employee

There is a limited distribution of the Independent Stream Forwarder available until Dec 1. Please contact your Technical Sales team to arrange for a time-limited test of this software.

0 Karma

ddrillic
Ultra Champion

The following speaks about it - Splunk Stream on a Raspberry Pi? YES!

It shows -

alt text

You said -

-- I've tried the documentation, my understanding is that I would have to have Splunk on a seperate machine, with RPI forwarding information to it. Is the Stream app not standalone? I would rather everything I need on the RPI alone without the need for a second machine.

So, as you said, the preferred way is to have Splunk on a separate machine and the forwarder and the App for Stream on the Raspberry Pi machine.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...