Splunk Enterprise

What should sourcename override and connection form filled in for UDP TCP in monitor when add data?

jliaw
Explorer

In monitor, using TCP and UDP sourcetype, what should be filled in at source name override and connection form be filled? And how to use the same port or remove the old port ?

Using Splunk llight, Windows10.

Tags (1)
1 Solution

manish_singh_77
Builder

jliaw
Explorer

Hi Manish. Thanks for your answer. I have read through the suggested web and have difficulty in looking the Splunk bin. Is that only available for Splunk enterprise? I'm using Splunk Light.

manish_singh_77
Builder

Hi jliaw,

It seems Splunk light have "$SPLUNK_HOME/bin/splunk" as per the below mentioned link.

"http://docs.splunk.com/Documentation/SplunkLight/7.1.1/Installation/UpgradeSplunkLight".

If you are using cloud version then you will not have access for the same, check & let me know in case of any queries.

jliaw
Explorer

Thanks for your answer! I will find out more about Splunk Light free trial Vs Splunk light and Splunk Light free Vs Splunk Enterprise free trial.

manish_singh_77
Builder

Sure, please check and let me know if you have any queries, I will also try to get more detailed information on it.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...