Forums: SplunkGeneral: Splunk Agent

Previous Topic: Splunk 3.3 in lightweight forwarder mode. Crashing.  |   Next Topic: Upgrading Splunk 3.2.3 to 3.3


Posts 1–2 of 2  |  Post to this topic

Hi,

We are using Splunk in our Development environment and are currently using the SYSlog Appender feature in "log4j.xml" to index relevant application log files to our Splunk server. We would like to move to a different model/format by utilizing what I believe to be, "Splunk Agents" instead of the "log4j.xml" file. I'm assuming that this involves installing a Splunk piece (or Agent) on each server whose log files we want to index. Is that a correct assumption? If so, how does one install these Agents on the individual servers? I've looked through your on-line Administration Manual, but didn't find anything about installing and using Splunk Agents.

Thank you,

What you can do is load splunk and then set it as a lightweight forwarder mode (search "forwarder" in the documentation. You can set all the parameters locally and then have that sent to a central splunk indexing server.

There is a slight catch. the central splunk indexing server requires a paid license for it to be able to receive information from other splunk servers.

The only way around it, is to somehow get the file to the indexing server somehow (outside of using splunk forwarders.)

Post to this topic

You must be logged in to post a reply.










close

Flash required to play this video.

Click here to download the free Flash Player.

Description:

Permalink: