{"id":30449,"date":"2022-06-27T12:26:39","date_gmt":"2022-06-27T12:26:39","guid":{"rendered":"https:\/\/www.devopsschool.com\/blog\/?p=30449"},"modified":"2022-12-23T05:52:33","modified_gmt":"2022-12-23T05:52:33","slug":"splunk-tutorial-setup-splunk-server-indexer-search-head-universal-forwarder","status":"publish","type":"post","link":"https:\/\/www.devopsschool.com\/blog\/splunk-tutorial-setup-splunk-server-indexer-search-head-universal-forwarder\/","title":{"rendered":"Splunk Tutorial: Install &#038; Configure Splunk Server (Indexer + Search Head + Universal forwarder)"},"content":{"rendered":"\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-1\" data-shcb-language-name=\"PHP\" data-shcb-language-slug=\"php\"><span><code class=\"hljs language-php\">Setup Splunk(Indexer + Search Head) &#91;LICENSE SERVER ]\n========================================================\n$ sudo-s\n$ cd \/opt\n$ wget -O splunk<span class=\"hljs-number\">-8.0<\/span><span class=\"hljs-number\">.4<\/span><span class=\"hljs-number\">.1<\/span>-ab7a85abaa98-Linux-x86_64.tgz <span class=\"hljs-string\">'https:\/\/www.splunk.com\/bin\/splunk\/DownloadActivityServlet?architecture=x86_64&amp;platform=linux&amp;version=8.0.4.1&amp;product=splunk&amp;filename=splunk-8.0.4.1-ab7a85abaa98-Linux-x86_64.tgz&amp;wget=true'<\/span>\n$ tar -zxvf splunk<span class=\"hljs-number\">-8.0<\/span><span class=\"hljs-number\">.4<\/span><span class=\"hljs-number\">.1<\/span>-ab7a85abaa98-Linux-x86_64.tgz\n$ cd splunk\n$ cd bin\n$ .\/splunk start --accept-license \nhttp:<span class=\"hljs-comment\">\/\/15.206.149.89:8000\/<\/span>\nadmin\/admin123\n\n--------------\n<span class=\"hljs-number\">1.<\/span> Settings =&gt; Monitoring console =&gt; Setting =&gt; Forwarder Monitoring Setup =&gt; Forwarder Monitoring (ENABLE with <span class=\"hljs-number\">15<\/span> mins)\n<span class=\"hljs-number\">2.<\/span> Settings =&gt; Forwarding <span class=\"hljs-keyword\">and<\/span> Recieving =&gt; Receive data =&gt; Add <span class=\"hljs-keyword\">New<\/span> ==&gt; Listen on this port (<span class=\"hljs-keyword\">For<\/span> example, <span class=\"hljs-number\">9997<\/span> will receive data on TCP port <span class=\"hljs-number\">9997<\/span>)\n<span class=\"hljs-number\">3.<\/span> Restart a Splunk Instance\nSettings =&gt; Server Controls =&gt; Restart Splunk\n\nSetup universal forwarder\n========================================================\n$ sudo-s\n$ cd \/opt\n$ wget -O splunkforwarder<span class=\"hljs-number\">-8.0<\/span><span class=\"hljs-number\">.4<\/span><span class=\"hljs-number\">-767223<\/span>ac207f-Linux-x86_64.tgz <span class=\"hljs-string\">'https:\/\/www.splunk.com\/bin\/splunk\/DownloadActivityServlet?architecture=x86_64&amp;platform=linux&amp;version=8.0.4&amp;product=universalforwarder&amp;filename=splunkforwarder-8.0.4-767223ac207f-Linux-x86_64.tgz&amp;wget=true'<\/span>\n$ tar -zxvf splunkforwarder<span class=\"hljs-number\">-8.0<\/span><span class=\"hljs-number\">.4<\/span><span class=\"hljs-number\">-767223<\/span>ac207f-Linux-x86_64.tgz\n$ cd splunkforwarder\n\n<span class=\"hljs-comment\"># Create this file with some STRUCTURED Content<\/span>\nvi \/opt\/unitest.csv\n\nname,age,city,skill\ndevopsschool1,<span class=\"hljs-number\">22<\/span>,hyd1,devops1\ndevopsschool2,<span class=\"hljs-number\">23<\/span>,hyd2,devops2\ndevopsschool3,<span class=\"hljs-number\">24<\/span>,hyd3,devops3\ndevopsschool4,<span class=\"hljs-number\">25<\/span>,hyd4,devops4\n\nSetting up output.conf\n$ .\/bin\/splunk add forward-server <span class=\"hljs-number\">15.206<\/span><span class=\"hljs-number\">.149<\/span><span class=\"hljs-number\">.89<\/span>:<span class=\"hljs-number\">9997<\/span> --accept-license \n$ .\/bin\/splunk <span class=\"hljs-keyword\">list<\/span> forward-server\n\nSetting up input.conf\n$ .\/bin\/splunk <span class=\"hljs-keyword\">list<\/span> monitor \n$ .\/bin\/splunk add monitor \/opt\/unitest.csv\n$ .\/bin\/splunk add monitor \/<span class=\"hljs-keyword\">var<\/span>\/log\n$ .\/bin\/splunk <span class=\"hljs-keyword\">list<\/span> forward-server\n\n\n$ .\/bin\/splunk restart\n$ ps -eaf | grep splunk\n$ .\/bin\/splunk <span class=\"hljs-keyword\">list<\/span> forward-server\n<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-1\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">PHP<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">php<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","_joinchat":[],"footnotes":""},"categories":[2],"tags":[],"class_list":["post-30449","post","type-post","status-publish","format-standard","hentry","category-uncategorised"],"_links":{"self":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/30449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/comments?post=30449"}],"version-history":[{"count":2,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/30449\/revisions"}],"predecessor-version":[{"id":30458,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/30449\/revisions\/30458"}],"wp:attachment":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/media?parent=30449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/categories?post=30449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/tags?post=30449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}