Installation

Difference between Splunk app and splunk add-on and universal forwarder?

gsrikanth87
Path Finder

As per my understanding we install Splunk app on serverside, Splunk universal forwarder is client-side, then what is a Splunk add-on?

Labels (3)
1 Solution

kml_uvce
Builder

yes , if your definition of client and server side like this
client side is your source of data/system
serverside is your indexer

kamal singh bisht

View solution in original post

kml_uvce
Builder

yes , if your definition of client and server side like this
client side is your source of data/system
serverside is your indexer

kamal singh bisht

gsrikanth87
Path Finder

oh, Thank you. Do we have any video link for splunk configuration for unix/linux servers monitoring?

0 Karma

kml_uvce
Builder

universal forwarder : it is used to send data from source to indexer
Splunk app: you need to install in indexer or search head and shows you report, visualization
splunk addon:you need to install splunk add-on in forwarder and addon extract the data from source (example run scripts in unix addon) v and send to indexer via forwarder

kamal singh bisht
0 Karma

gsrikanth87
Path Finder

Thank you.. But I want to understand that where we install splunk app and splunk fowarder?

splunk app - server side
splunk universal forwarder- client side with addon

Is this correct?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...