Hi All,
We wanted to monitor our *nix environment using Splunk, what is the best approach 1)Setup splunk enterprise and use Splunk App or 2) Setup splunk forwarders and use splunk Add-on??
We have close to 100+ servers.
Regards,
BK
Hi bharathkumarnec,
As you can find in the Splunk App for *nix documentation (http://docs.splunk.com/Documentation/UnixApp/latest/User/AbouttheSplunkAppforUnix), you have to distribute tha TA-nix on all your forwarder to take all the inputs to use in the Splunk App for *nix.
Bye.
Giuseppe
Hi,
I suggest you have a look at Nmon, a complete and powerful monitoring and capacity planning solution for Linux:
https://splunkbase.splunk.com/app/1753/
And make your own opinion.
Cheers,
Guilhem
All of the above.
1st you need splunk enterprise installed somewhere.
Then you need to install the Splunk universal forwarder on all the nix hosts.
Then you need to install the Splunk TA for nix on all the universal forwarders AND on the Splunk enterprise server(s) and enable the inputs you want on the forwarders. Also enable the data forwarding from the forwarders to the Splunk enterprise server(s).
Finally you can install the Splunk app for nix on the server running splunk enterprise.
Although the Splunk app for nix is not required, it does contain some neat visualizations and out-of-the-box visualizations.
Thank you! That was the missing bit for https://answers.splunk.com/answers/521110/how-to-install-the-splunk-add-on-for-unix-and-linu.html#an... (http://docs.splunk.com/Documentation/UnixAddOn/5.2.4/User/Platformandhardwarerequirements is lying!)
Hi bharathkumarnec,
As you can find in the Splunk App for *nix documentation (http://docs.splunk.com/Documentation/UnixApp/latest/User/AbouttheSplunkAppforUnix), you have to distribute tha TA-nix on all your forwarder to take all the inputs to use in the Splunk App for *nix.
Bye.
Giuseppe