Splunk Cloud Platform

How to connect a heavy forwarder to Splunk Cloud?

Dayane_tr
Path Finder

Hello,

I have a linux machine where Splunk Enterprise is installed and I would like to use Heavy forwarder to send the files to the cloud.

How do I install the "app"(splunkclouduf.spl)  from the cloud instance in Splunk Enterprise? 

I don't have access to the Splunk Enterprise web interface, only access to the linux machine.

Regards

Labels (2)
Tags (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

I never remember the proper syntax, but it's either

/opt/splunk/bin/splunk app install app_package.spl

or

/opt/splunk/bin/splunk install app app_package.spl

 

0 Karma

Roy_9
Motivator

@Dayane_tr  After the untar is done as rich suggested, you should open a FW connection from HF to Splunk Cloud(basically will be as inputs*.abc.splunkcloud.com) something like that on port 9997.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Install the app like you would install any other app on the command line.  Untar the file to $SPLUNK_HOME/etc/apps then restart the HF.

tar -zxf splunkclouduf.spl -C /opt/splunk/etc/apps
---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...