Splunk Enterprise

How to view Splunk Enterprise Data on itself?

skrampachspl
Loves-to-Learn Lots

I hate to have a newbie question here but, I am deploying a Linux Splunk server with several windows workstations. The workstations show up in the forwarders area however, I cannot find the hostname of the Linux server I am on. Do I need to include a forwarder on the splunk server? I have never worked at the application level with splunk before so I apologize if this is a silly question.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you have a single splunk server (SH + IDX on same node), then the easiest way is just install those apps directly into that node (don't use DS for that!!) to collect needed logs/events. If you have indexer cluster then use it to deliver apps to individual search peers.

Another way is use a UF on that/those nodes and install apps with it, but usually it's better to install those into splunk server(s).

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...