So I’d like to introduce you to a new piece of technology we have released this week, the Splunk Universal Forwarder for Linux ARM (Raspberry Pi). Tested for deployment on Raspberry Pi, this version of the forwarder is designed to allow end users to capture data on embedded, low power ARM based devices and forward that data to Splunk Enterprise, Cloud, Storm, or Free instances. You can download the release, for free, right now at http://apps.splunk.com/app/1611/
I’ve got to assume that this forwarder will be a first introduction to Splunk for many in the Raspberry Pi community, so let me briefly tell you a bit about Splunk, its purpose, its architecture, and how to get started. I’ll also link you to the necessary documentation. If all goes well, you should be up, searching, analyzing and building dashboards with data from your Pi’s in less than a few hours.
First, Splunk’s mission is to make machine data accessible, useable and valuable to everyone. We feel strongly that “everyone” should include the maker community as well. You all are building tomorrow’s technology today, and I hope being able to take advantage of Splunk’s innovative analytics technology, search language, and dashboards will greatly accelerate and enhance your Raspberry Pi based projects.
Splunk can run as a standalone instance, but one of its most powerful and flexible features is its capability to receive large volumes of data from many distributed Splunk “Forwarders”. These Universal Forwarders are designed to be extremely lightweight Splunk instances who’s primary purpose is to take any data from the local machine and forward it to a Splunk index on another machine. They can be deployed in the thousands, all reporting data in near real-time back to a single Splunk indexer. They can be mass configured as well, and configuration of data inputs can be centrally managed. A Universal Forwarder is a perfect piece of technology for smaller computing systems like the Raspberry Pi as it can take any data from the Pi’s local logs, local scripts, and attached sensors and shields and send it quickly over the network to another instance of Splunk. For more on Splunk’s capability as a distributed data platform, please check out http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Distributedoverview.
For documentation on installing a Universal Forwarder, please see http://docs.splunk.com/Documentation/Splunk/6.0/Forwarding/Introducingtheuniversalforwarder. The installation information for *nix should work just fine. Please don’t forget to set Splunk to run on boot: http://docs.splunk.com/Documentation/Splunk/6.0/Forwarding/Deployanixdfmanually. For a basic introduction to Splunk, take a look at our general documentation http://docs.splunk.com/Documentation. And remember, Splunk is always available as a free download from http://www.splunk.com/download.
Hope you enjoy, and please let me know of any cool projects you are doing with Pi and Splunk. I’d love to highlight a few right here in this blog!