Getting ready

To step through this recipe, you will need a server with the Splunk Universal Forwarder installed but not configured. You will also need a running Splunk Enterprise server. No other prerequisites are required.

To obtain the Universal Forwarder software, you need to go to https://www.splunk.com/download and register for an account if you do not already have one. Then, either download the software directly to your server or download it to your laptop or workstation and upload it to your server using a file transfer process such as SFTP. For more information on how to install and manage the Universal Forwarder, visit https://docs.splunk.com/Documentation/Forwarder/latest/Forwarder/Abouttheuniversalforwarder.

Get Splunk Operational Intelligence Cookbook - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.