Splunk Enterprise

What should sourcename override and connection form filled in for UDP TCP in monitor when add data?

jliaw
Explorer

In monitor, using TCP and UDP sourcetype, what should be filled in at source name override and connection form be filled? And how to use the same port or remove the old port ?

Using Splunk llight, Windows10.

Tags (1)
1 Solution

manish_singh_77
Builder

jliaw
Explorer

Hi Manish. Thanks for your answer. I have read through the suggested web and have difficulty in looking the Splunk bin. Is that only available for Splunk enterprise? I'm using Splunk Light.

manish_singh_77
Builder

Hi jliaw,

It seems Splunk light have "$SPLUNK_HOME/bin/splunk" as per the below mentioned link.

"http://docs.splunk.com/Documentation/SplunkLight/7.1.1/Installation/UpgradeSplunkLight".

If you are using cloud version then you will not have access for the same, check & let me know in case of any queries.

jliaw
Explorer

Thanks for your answer! I will find out more about Splunk Light free trial Vs Splunk light and Splunk Light free Vs Splunk Enterprise free trial.

manish_singh_77
Builder

Sure, please check and let me know if you have any queries, I will also try to get more detailed information on it.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...