Splunk Enterprise

How to view Splunk Enterprise Data on itself?

skrampachspl
Loves-to-Learn Lots

I hate to have a newbie question here but, I am deploying a Linux Splunk server with several windows workstations. The workstations show up in the forwarders area however, I cannot find the hostname of the Linux server I am on. Do I need to include a forwarder on the splunk server? I have never worked at the application level with splunk before so I apologize if this is a silly question.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

If you have a single splunk server (SH + IDX on same node), then the easiest way is just install those apps directly into that node (don't use DS for that!!) to collect needed logs/events. If you have indexer cluster then use it to deliver apps to individual search peers.

Another way is use a UF on that/those nodes and install apps with it, but usually it's better to install those into splunk server(s).

r. Ismo

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...