Hi, our requirement is to install SNMP Modular Input but we are not sure yet how and where are we required to configure it in Splunk deployment? Please help.
Thanks!
Yes it can , this is a common deployment architecture, particularly for high volume OID polling.
When deploying to a UF , there is no confgi UI , so you edit the SNMP stanza in an inputs.conf file manually.
All files live on the UF , just untar or push out the SNMP app to etc/apps.
thanks @Damien...sorry for the late response as we focused on different feed lately. We'll get into this again once we are back on the requirement 🙂
Yes it can , this is a common deployment architecture, particularly for high volume OID polling.
When deploying to a UF , there is no confgi UI , so you edit the SNMP stanza in an inputs.conf file manually.
All files live on the UF , just untar or push out the SNMP app to etc/apps.
for a deployment that have several servers with UF on them, is it advisable to have the smnp_ta installed via DS and push them to forwarder together with the inputs.conf changes? or manually doing it? do you have any documentation specific on the TA implementation on distributed deployment?