Splunk Dev

Running Splunk on Raspberry Pi 3

calebra05
New Member

Dear Splunkers,

I would like to install Splunk on my Raspberry Pi 3 just to monitor some (network) devices (one NAS, one router and a PC at first) at home.
Does Pi3 has enough hardware resource to run Splunk (and maybe other services)?

Here are the specifications:
SoC: Broadcom BCM2837
CPU: 4× ARM Cortex-A53, 1.2GHz
GPU: Broadcom VideoCore IV
RAM: 1GB LPDDR2 (900 MHz)

Thank you in advance!

Tags (4)
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

As far as I'm aware there are no Splunk Enterprise binaries compiled for ARM available, just a universal forwarder: http://blogs.splunk.com/2013/10/11/introducing-the-splunk-universal-forwarder-for-raspberry-pi/

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

As far as I'm aware there are no Splunk Enterprise binaries compiled for ARM available, just a universal forwarder: http://blogs.splunk.com/2013/10/11/introducing-the-splunk-universal-forwarder-for-raspberry-pi/

calebra05
New Member

It's a pity, but thank you for the answer.

0 Karma

Lowell
Super Champion

Please note that recent version of the Raspberry PI Splunk UF is available from the regular universal forwarder download page, under the Linux tab. Look for the "ARMv6" architecture. The package is available as a *.tgz file.

(The announcement link above, links to the app on Splunk base (which is really an old 6.0 download). The latest version is supported by Splunk and available via the standard download channel.)

BongoTheWhippet
Path Finder

That download actually fails (neither the wget or the direct link work anymore) so the OP is correct - there's no more options for Raspberry Pi forwarding which is a shame as it is the No. 1 selling computer in the world!

0 Karma

MuS
Legend

Well, there is a ARMv6 version of the UF to download here https://www.splunk.com/en_us/download/universal-forwarder.html#tabs/linux and I was able to download splunkforwarder-7.2.0-8c86330ac18-Linux-arm.tgz from there.

Also I was able to download an older version using wget like this:

wget -O splunkforwarder-6.6.0-1c4f3bbe1aea-Linux-arm.tgz 'https://www.splunk.com/page/download_track?file=6.6.0/linux/splunkforwarder-6.6.0-1c4f3bbe1aea-Linux-arm.tgz&ac=&wget=true&name=wget&platform=Linux&architecture=ARM&version=6.6.0&product=universalforwarder&typed=release'

cheers, MuS

0 Karma

BongoTheWhippet
Path Finder

Ah indeed, you can download from the webpage, but the latest 7.2.x version fails to wget correctly.

Not ideal, but workable if you grab it from the webpage and SCP it to your RPi.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...