Installation

Can we install a Splunk Universal Forwarder on an actual Splunk server?

Gregski11
Contributor

so I want to know how long our Splunk servers have been up for, I got the query and it works great on hundreds of other servers but not on our two dozen Splunk servers (Cluster Master, Deployment Servers, Indexers, Search Heads, etc.) I think it is because we do not have the Universal Forwarder installed on them, so can we install it on the Splunk servers or am I dense and missing something and we can just use some of the Splunk Enterprise component to send Even Log data to our Indexers

Labels (1)
0 Karma

gcusello
Esteemed Legend

Hi @Gregski11,

you don't need to install a forwarder on your Splunk servers, you have only to forward their internal logs to Indexers.

You can do this in a simple way: [Settings -- Forwarding and receiving -- Forwarding].

This is a best practice for all Splunk infrastructure, in this way you can monitor your Splunk infrastructure using the Splunk Monitoring Console App.

Ciao.

Giuseppe

0 Karma

Gregski11
Contributor

@gcusello wrote:

Hi @Gregski11,

you don't need to install a forwarder on your Splunk servers, you have only to forward their internal logs to Indexers.

You can do this in a simple way: [Settings -- Forwarding and receiving -- Forwarding].

This is a best practice for all Splunk infrastructure, in this way you can monitor your Splunk infrastructure using the Splunk Monitoring Console App.

Ciao.

Giuseppe


the Monitoring Console does not give us what we need? I want to be able to see how long our Splunk servers have been up for, ie how many days?

0 Karma

Gregski11
Contributor

thanks, this is what I see, does this mean this Search Head is not configured to forward it's data to an Indexer? 

 

Forwarding and receiving.png

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...