Splunk Enterprise

How can install splunk indexers in centos?

pacifikn
Communicator

Greetings!!!

 

How can i  install splunk indexers in centos 7?

What I will need and what are steps to follow ?

 

I need to setup splunk TEst Environment, So far I have only installed Splunk enterprise as Search Head and I am able to browse it through web GUI and create users, I need also to INSTALL SPLUNK INDEXERS? AND splunk forwarder, and also install splunk management node that will be able to receive syslog from network security devices source and manages search head , KINDLY HELP me and guide me with the steps???

Thank you in advance!!!

Labels (2)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Installing an indexer is the same as installing a search head.  Once installed, go to Settings->Forwarding and Receiving on the indexer to enable reception of data on port 9997.  Then go to Settings->Distributed Search on the search head to connect the SH to the indexer.

TBH, what you're asking for here is the topic of a week-long Splunk course (and a certification exam) so it's too much to cover in an Answer.  However, each of the instances in your question is covered by at least one manual at docs.splunk.com.

Installing a forwarder is very similar to installing Splunk Enterprise, but with a different binary.  You'll need to modify the forwarder's outputs.conf file to point to your indexer(s).

Splunk management node don't receive syslog.  They only manage other Splunk instances.  To receive syslog, use a dedicated syslog server such as syslog-ng to write the events to files which are monitored by a forwarder.

And if you expect to ingest more than 500MB a day you'll need a license.  Install the license on the SH or management node and point the indexer(s) to that instance (Settings->Licensing->Change to peer.

I'm sure you'll have more questions as you go.  Feel free to come back with more specific questions when you get stuck.

---
If this reply helps you, Karma would be appreciated.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...