JBOSS Admin

Monday, June 21, 2010

Splunk forwarding and receving

1) Install Splunk server
2) Install Splunk on host machines you want to monitor. Please have splunk forwarder license on the host.
3) Setup Splunk server as a receiver and the splunk on other target systems as forwarder

4) Setup Receiver
Navigate to Manager > Forwarding and Receiving > Receive data > Configure receiving > New
Set up port as 8090 or any available  port
Restart splunk

5) Setup Forwarder
Navigate to Manager > Forwarding and Receiving > Forward data > Configure forwarding > New
Provide {splunk_server_ip_from_step4):8090
Restart splunk

Note: If you are copying splunk install from one machine another, please do this step
Login to Splunk
Navigate to Manager > System settings > General settings
Splunk server name and Default host name should match the host name
Save and restart.

posted by Jayanthi Krishnamurthy @ 5:29 PM   0 Comments

0 Comments:

Post a Comment

Subscribe to Post Comments [Atom]

<< Home

Newer›  ‹Older

About Me

Name: Jayanthi Krishnamurthy

View my complete profile

Posts

  • Splunk forwarding and receving

Older Posts Newer Posts

Archives

Subscribe to
Posts [Atom]