Getting Data In

what is Index , search and Heavy forwarder and how they are related each other please i need help

sujeet11dec
New Member

I have 3 Ubuntu machine , but i dont know what index , search and heavy forwarder and how they are related to each other .

Please help me i am vary new into IT Security and i got splunk as an first project

Tags (2)
0 Karma

n00badmin
Communicator

Have you installed Splunk Enterprise on the machines?

0 Karma

n00badmin
Communicator

You simply need to install Splunk Enterprise on 3 linux machines and configure one to forward and one to be a search only.

http://docs.splunk.com/Documentation/Splunk/latest/Installation/Whatsinthismanual

0 Karma

sujeet11dec
New Member

Hi n00badmin

Please i need your small help here what need to be a machine work as index , search or heavy Forwarder as per configration wise

sujeet

0 Karma

n00badmin
Communicator

First you should do some reading. Splunk documentation is some of the best

http://docs.splunk.com/Documentation/Splunk

A heavy forwarder is a full install of splunk that forwards data to an indexer.

The indexer indexes the data into indexes searchable from the searchhead.

START HERE : http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview

0 Karma

sujeet11dec
New Member

Please i need brief answer

0 Karma
Get Updates on the Splunk Community!

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...