...apps pushed down to these forwarders as follows:
App1 – indexer_config: Sets outputs.conf to point to indexer and defines clientCert and sslRootCAPath cert.
App2 – Splunk_TA_Windows: This App configure...
I need toconfigure the Splunk Add-on for Linux in both forwarder and Splunk server machines. I have Splunk Enterprise running on windows and collecting the logs from Linux using Splunkforwarder....
I cannot figure out which component to enable HEC and where tosend the events. We have an on prem Splunk Enterprise distributed configuration with a Deployment server, Indexer and SearchHead. We a...
I'm trying to plan an, for me, large deployment. Connecting several sites to a headquarter. Each site does have from 200 to 900 clients who need tosenddatato the indexer. on two locations the b...
One of the main questions we have right now is - where are the Universal Forwarders installed? We had talked about having them on each client and having a deployment server to control pushing c...
We offer a third party solution (Alliance LogAgent) that sends IBM i security events in syslog format toSplunk in real time. It works great for in-house deployments, but we have prospective c...
...s false in forwarder side.
In this case, I think that it doesn't have toconfigure clientCert AND serverCert , am I wrong?.
https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/ConfigureSplunkforwardingtousethedefaultcertificate
I was hired in an organization as a Splunk onboard specialist, I don't know much about onboarding data. I had gone through getting data in docs but that is not helpful to deal in real time.
Our e...
Is it possible to change the Master node server ip?
I have to change the current Master node with a new machine but I can not reuse the same IP. Which problems I will meet with a new ip?
Thanks a...