Installation

Splunk installation

rageshkg
New Member

HELLO,
We need help configuring splunk forwarder in Linux environment, we have around 70 Linux appliances where we need to divert the syslog messages to slunk.

I have installed forwarder agent as per installation document but logs are not getting received at splunk end, can you please help us on this matter.

I have the details of the splunk UDP port which would be receive the logs.

Regards,
Ragesh

Tags (1)
0 Karma

Richfez
SplunkTrust
SplunkTrust

If you have installed the Universal Forwarder on each of your hosts, there's a bit of configuration to do.

First, though, let's take a step back. You mentioned a Splunk UDP port to receive the logs? Usually the UF to Indexer (E.g. "the Splunk server") commmunication is direct Splunk data on TCP port 9997. Review again the overall steps to getting data in. That first step - setting up a receiving server - is documented in another section on Enabling a receiver. So that's step 1.

Now, on each of the systems you want to monitor, you'll need to set up an app or two and enable some inputs. While manually installing the Splunk Add-on for Unix or Linux might work to test some things and prove it out, with 70 linux boxes to monitor you will want to use some other mechanism. You could use Puppet or Chef or any number of things to manage configs if you have experience in those, but if not I'd suggest starting with the Deployment Server. This is enabled already on your Splunk server, so you have to have a) provide it things to deploy and b) configure your clients to use it as a deployment server. I think that's worthy of your own research (start from reading about the deployment server, being sure to take your time and get a full understanding before diving in. If you have questions there, it's probably worth a new question.

Anyway, back to the point. So, let's assume a manual install of an app or two on a handful of test systems. Or that you'll be a glutton for punishment and do them all manually. Or maybe you have some interns who need busywork. Whichever. 🙂

First, configure each instance to send its data to your main Splunk server. Here's a page about forwarding, and one more specifically for configuring the outputs to go where you need them to go.

On each client, install the Add-on as noted above. There is documentation available for all of this, including that app. I'm just giving you the general idea, there's a lot of specifics to cover.

All that should remain to be done is to configure which logs you'd like to send in. That's covered in the documentation for the Add-on right above.

So, all in all it's not the simplest of processes. But it's a LOT easier when you start to learn the terminology involved and know what to search for in Splunk's Documentation. Their documentation really is great, but there's quite a bit of it and the product has some specialized needs and terminology that without which, you'd get a bit lost.

So I hope this helps!

Happy Splunking!
-Rich

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...