Getting Data In

forwarder Or universal forwarder

jimjohn
Path Finder

I have a splunk 6.0.1 installed in my system.
Can i set my mechine as forwarder and receiver.
I need to read vales from DB and forward to same mechine.
Can anybody show tutorials to this.

Also it will be helpful if you can tell me how to set up universal forwarder.

Thanks
Jim John

0 Karma

MuS
Legend

Hi jimjohn,

If you just want to query a DB and forward it to your local Splunk Server, then there is no need to install and setup an universal forwarder in this use case.
Follow the docs on how to Setup DB connect in your local Splunk Server UI and you can use the dbquery search command to get results from the DB directly into your local Splunk Server.

Usually an universal forwarder is installed on remote servers to get data into Splunk.

Hope this helps ...

cheers, MuS

0 Karma

MuS
Legend

according to the docs DB connect should be setup on the search head (the web interface where you do the searches) http://docs.splunk.com/Documentation/DBX/latest/DeployDBX/Otherdeploymentconsiderations . nothing mentioned about setup on universal forwarder though......

0 Karma

jimjohn
Path Finder

Last question .
I want to configure DB fetching operation in universal forwarder.
Is it possible? If so please have any tutorials or links

0 Karma

MuS
Legend

sure you can do this, here is some intro about the universal forwarder http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Introducingtheuniversalforwarder also read http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Aboutforwardingandreceivingdata and last but not least don't forget to enable receiving on the indexer http://docs.splunk.com/Documentation/Splunk/6.0.1/Forwarding/Enableareceiver

hope this helps...

0 Karma

jimjohn
Path Finder

OK,
I did DB connect in local.
Can you please provide tutorials for configuring universal forwarder.
For testing purpose is it possible to use splunk and universal forwarder in same machine.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...