Monitoring Splunk

Universal forwarder sidecar deployment- Where to locate user and password, and confusion with url?

DukeScottWu
New Member

Hey community

We are using Universal forwarder as a sidecar in K8S following github introduction.

But the document is not clear enough and cannot guide us to integrate with server.

env:
           - name: SPLUNK_START_ARGS
             value: --accept-license
           - name: SPLUNK_USER
             value: root
           - name: SPLUNK_GROUP
             value: root
           - name: SPLUNK_PASSWORD
             value: helloworld
           - name: SPLUNK_CMD
             value: add monitor /var/log/
           - name: SPLUNK_STANDALONE_URL
             value: splunk.company.internal
 

Some questions for about configurations:

1. splunk user and password:  where can we get this user and password? shall we allocate an account from splunk enterprise server?

2. SPLUNK_STANDALONE_URL:   is this splunk enterprise server URL?  is it possible to get this URL from splunk server?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...