Installation

How to deploy Splunk on AIX/Unix servers for server performance monitoring?

gsrikanth87
Path Finder

Hallo,

We have 90 AIX/Unix servers. We are planning to implement Splunk on them. Now I have 2 to 3 test servers with me. Can you please explain me where to install the splunk applications and step by step procedure? For example:

ser1- splunk app(server)
ser2- splunk forwarder with addon (client1)
ser3- splunk forwarder with addon (client2)

If the above is correct, could you please explain the step by step procedure to deploy Splunk for system monitoring?

Labels (1)

yannK
Splunk Employee
Splunk Employee

for details about the deployment
http://docs.splunk.com/Documentation/UnixApp/5.1TA/User/AbouttheSplunkTechnicalAdd-on%28TA%29forUnix...

For the Unix app, you need :

  • the "Splunk App for Unix and Linux" on the search-head (for the dashboards)
    download here https://apps.splunk.com/app/273/

  • the "Splunk Add-on for Unix and Linux" on the indexers (for the indexes and sourcetype definitions), and on the forwarders (for the monitoring inputs and scripts)
    download here https://apps.splunk.com/app/833

The extra step will be to preconfigure the add-on to enable the inputs you want before deploying it to the forwarders.
I recommend to use a full standalone splunk install, install the add-on, and enable the inputs using the UI. Then once satisfied, use this configured app (the modified setting must be in the $SPLUNK_HOME/etc/apps/appname/local/ folder if you want to check)

If you have a large number of Unix forwarders to monitor, you may want to use the deployment-server to deploy the preconfigured app at once.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...