Documentation: 3.4.1
Print Version Contents
This page last updated: 12/09/08 01:12pm

Enable the Splunk light forwarder via the deployment server

Splunk 3.4 introduces the Splunk light forwarder application. Enabling this application on your Splunk deployment client configures it to be a Splunk light forwarder. This application is installed with Splunk 3.4 and later by default, but is not enabled by default.

Once you've installed Splunk on your deployment clients, you can use the Splunk deployment server to enable the Splunk light forwarder application.

To do this, you must first have set up a deployment server and clients. Then, deploy the $SPLUNK_HOME/etc/modules/distributedDeployment/classes/EnableLightForwarder server class using the standard deployment instructions. This restarts Splunk on the deployment client, and enables the light forwarder.

You can configure the deployment client to monitor the files and directories you're interested in either before or after you enable the light forwarder. Refer to these recommendations before proceeding.

Note: You cannot use "round-robin" forwarding in conjunction with the light forwarder because the data is not parsed before being sent--events may be split into parts before reaching the receiver, resulting in partial events.

Comments

No comments have been submitted.

Log in to comment.