Knowledge Management

Splunk on a read only file system



We have an application server which has a vendor requirement to operate in read only. We can install taking in/out of read only mode. But it MUST be in read only mode to operate. Is it possible the universal forwarder can operate in this situation?

Tags (1)
0 Karma


Universal forwarder might work for this, but it would be useful to know what types of inputs you want to use. If the forwarder doesn't work you could always push the data to your splunk server using scp or something similiar (or mount your log directory from the splunk server).

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...