I'm new to Splunk and haven't found the exact answer that I'm looking for, so I'm hoping this is the right place to ask for help.
My goal is to successfully install a light forwarder on one of my application servers, index a log file and then send that data back to my main Splunk server.
Right now, my environment is 100% Windows. I have a new server that I have installed Splunk on. I want to use this as a central server for collecting all logs across my cluster. For now, I simply want to test collecting data from a single app server. What does the workflow look like for this task? Conceptually, I think I should setup my main Splunk server as a deployment server, configure a deployment class, install Splunk on the application server, configure it as a light forwarder and point it back at the main Splunk server and then assign the correct deployment class to the forwarder. Is this correct?
If someone would confirm that these are the correct steps (or, if they are wrong, provide the right steps) and then offer a semi-detailed run-down of what it takes to get this setup running, I would be very grateful.
Thank you.
... View more