Splunk Search

Deployment,Search Head,Indexer,Forwarder simple setup

rjantarasami
New Member

Please correct my simple step by step in linux environment:

Forwarder :
-Install splunkforwarder, accept license, enable boot-start.
-/opt/splunkforwarder/bin/splunk add forward-server ip-myindexer-server:9997
-/opt/splunkforwarder/bin/splunk list forward-server
-/opt/splunkforwarder/bin/splunk add monitor /var/log/apache/logs/ -index main -sourcetype %app%

Indexer :
-install splunk enterprise, accept license, enable boot-start.
-/opt/splunk/bin/splunk enable listen 9997

Search Head :
I dont know how to add indexer using CLI ?

Deployment Server :
I dont know how to setup here ?

Tags (3)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...