Splunk Enterprise

How to view Splunk Enterprise Data on itself?

skrampachspl
Loves-to-Learn Lots

I hate to have a newbie question here but, I am deploying a Linux Splunk server with several windows workstations. The workstations show up in the forwarders area however, I cannot find the hostname of the Linux server I am on. Do I need to include a forwarder on the splunk server? I have never worked at the application level with splunk before so I apologize if this is a silly question.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you have a single splunk server (SH + IDX on same node), then the easiest way is just install those apps directly into that node (don't use DS for that!!) to collect needed logs/events. If you have indexer cluster then use it to deliver apps to individual search peers.

Another way is use a UF on that/those nodes and install apps with it, but usually it's better to install those into splunk server(s).

r. Ismo

0 Karma
Get Updates on the Splunk Community!

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...