Installation

Difference between Splunk app and splunk add-on and universal forwarder?

gsrikanth87
Path Finder

As per my understanding we install Splunk app on serverside, Splunk universal forwarder is client-side, then what is a Splunk add-on?

Labels (3)
1 Solution

kml_uvce
Builder

yes , if your definition of client and server side like this
client side is your source of data/system
serverside is your indexer

View solution in original post

kml_uvce
Builder

yes , if your definition of client and server side like this
client side is your source of data/system
serverside is your indexer

gsrikanth87
Path Finder

oh, Thank you. Do we have any video link for splunk configuration for unix/linux servers monitoring?

0 Karma

kml_uvce
Builder

universal forwarder : it is used to send data from source to indexer
Splunk app: you need to install in indexer or search head and shows you report, visualization
splunk addon:you need to install splunk add-on in forwarder and addon extract the data from source (example run scripts in unix addon) v and send to indexer via forwarder

0 Karma

gsrikanth87
Path Finder

Thank you.. But I want to understand that where we install splunk app and splunk fowarder?

splunk app - server side
splunk universal forwarder- client side with addon

Is this correct?

0 Karma
Get Updates on the Splunk Community!

.conf23 | Get Your Cybersecurity Defense Analyst Certification in Vegas

We’re excited to announce a new Splunk certification exam being released at .conf23! If you’re going to Las ...

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...