Hi, we just started testing/experimenting with Splunk. Followed a Splunk4Rookies workshop but that focussed on the SPL and dashboards, not on ingesting data. We got the docker-compose installation up and running. I have installed a universal forwarder on a linux server and was able to send /var/log to the splunk install. I find various post that state * I should be using the Splunk Add-on for Unix and Linux * it needs to be installed on the forwarder * I should be using a deployment server instead of configuring locally on the linux server. Looking for information on how to actually install a deployment server. I seem to be going in circles between pages with old comments (pre 2016, https://community.splunk.com/t5/Deployment-Architecture/How-to-configure-a-deployment-server/m-p/131015/thread-id/4975) and broken links, or page explaining why I would need a deployment server. Questions : Do I need to bother with deployment server at this stage ? Is it really bad if I install "Splunk Add-on for Unix and Linux" locally ? and how do I actually locally, the insatt Can you point me to a basic step by step explanation of how I can install a deployment server ? This is intended for a test, can we add the deployment server capability to our Splunk server created with docker compose ?
... View more