Deploy Heavy Forwarder with CLI

October 13, 2017
Splunk

Enable listener on a receiver (IDX)

idx$ splunk enable listen 9997 -auth admin:password

Enable HF on Heavy Fowarder

fwd$ splunk enable app SplunkForwarder -auth admin:password
fwd$ splunk restart
fwd$ splunk add forward-server idx:9997 -auth admin:password
Added forwarding to: idx1:9997.

注意点

ルーティングは、HF 上で行われる。

See also