Installation

Install UF/HF in Unisys Mainframe

SplunkDash
Motivator

Hi,

So far my know, Unisys Univac Mainframe series support Linux/Windows. Just wonder if we can install UF/HF in Unisys  Univac Mainframe SPAR. Any help would be appreciated.

Thank you and Regards,

 

Obaidul

 

Labels (3)
0 Karma

ianhss
Explorer

@SplunkDash Did you make any progress with this?  I am interested to learn if you managed to get anything working for Unisys 2200.

0 Karma

SplunkDash
Motivator

Not yet....still facing challenges on the file/data structure on UNIVAC 2200 vs SPLUNK compatibilities and also find out the ways to run OS supported by SPLUNK computational agents (Like UF). Thank you so much appreciate your support.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If the Univac is actually *running* Linux (not just "support") and the CPU type is one Splunk will run on then you should be able to install a forwarder on the mainframe.  To minimize potential problems, start with the UF.

If it doesn't run then perhaps you can write some code to forward events from the mainframe to Splunk using HEC.

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator
Thank you so much for you quick response. But how does it work? Like ......write   codes and place the codes in Unisys Univac Mainframe and then use HTTP Event Collector to send data to Splunk. Do I need to configure HEC protocol in mainframe and also  need to change format of character code to 7-bit ASCII if Mainframe data is in EBCDIC
 
Thank you and regards,
Obaidul 
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

By "code" I mean software (aka "a program").  It does not have to implement the "HEC protocol" since the HEC protocol is HTTP, which should be available on the mainframe.  Splunk prefers text in UTF-8 so you'll need to convert EBCDIC to that.

---
If this reply helps you, Karma would be appreciated.

SplunkDash
Motivator

Do you know what tools/codes/programs we should use to push the data from UNIVAC to SPLUNK Indexer when we use HEC protocol? Thank you and truly appreciate your support in these efforts.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I know next to nothing about UNIVAC systems so I can't help much.  If the system supports Python then consider using George Starcher's Python class for sending data to HEC.

https://github.com/georgestarcher/Splunk-Class-httpevent

---
If this reply helps you, Karma would be appreciated.
0 Karma

SplunkDash
Motivator

Excellent, makes sense to me.....thank you so much, truly appreciated!

 

Kind Regards,

Obaidul

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...