Splunk Enterprise

What should sourcename override and connection form filled in for UDP TCP in monitor when add data?

jliaw
Explorer

In monitor, using TCP and UDP sourcetype, what should be filled in at source name override and connection form be filled? And how to use the same port or remove the old port ?

Using Splunk llight, Windows10.

Tags (1)
1 Solution

manish_singh_77
Builder

manish_singh_77
Builder

jliaw
Explorer

Hi Manish. Thanks for your answer. I have read through the suggested web and have difficulty in looking the Splunk bin. Is that only available for Splunk enterprise? I'm using Splunk Light.

manish_singh_77
Builder

Hi jliaw,

It seems Splunk light have "$SPLUNK_HOME/bin/splunk" as per the below mentioned link.

"http://docs.splunk.com/Documentation/SplunkLight/7.1.1/Installation/UpgradeSplunkLight".

If you are using cloud version then you will not have access for the same, check & let me know in case of any queries.

jliaw
Explorer

Thanks for your answer! I will find out more about Splunk Light free trial Vs Splunk light and Splunk Light free Vs Splunk Enterprise free trial.

manish_singh_77
Builder

Sure, please check and let me know if you have any queries, I will also try to get more detailed information on it.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!