Splunk Enterprise

Configuration from Scratch

Keron
New Member

Im completely green using SPLUNK, I have downloaded enterprise, have a profile but I cannot seem to get it configured to work off of my home system. i.e testing SPLUNK on myself. The steps stop working for at the step for :"Configure the universal forwarder using configuration files" 

Im not understanding how to access the config settings through the CLI to move beyond this step.

Labels (1)
0 Karma

DaClyde
Contributor

At this point, you will basically be editing the various .conf (inputs, outputs, props, transforms) files in Notepad or some other text editor.  The CLI will mostly for issuing commands to Splunk, which in the beginning will be mostly ./splunk stop,  ./splunk start and ./splunk restart.

Are you running headless, or do you have access to the web interface?

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...