Hi All,
I wanted to know is there a way to get the data without installing forwarder on machine (Linux).
Thanks,
Pavan
Yes, there is. You can receive over TCP or UDP ports.
http://docs.splunk.com/Documentation/Splunk/latest/Data/Monitornetworkports
ok, do i need configure anything in client side. i configured TCP 514 port in Data input. Please let me know if anything need to configured to get the data.
Thanks