官术网_书友最值得收藏!

Configuring a TCP input

On all of the indexers, you will need to configure a TCP input for receiving the forwarded internal logs from the other Splunk servers; this input can service forwarded data from universal forwarders as well:

  1. Settings | Forwarding and receiving | Configure receiving | New Receiving Port (button)
  2. Listen on this port: 9997
  3. Save

Splunk will create or append an inputs.conf file in /opt/splunk/etc/system/local/ with the following content:

[default]
host = 172.31.28.223

[splunktcp://9997]
connection_host = ip

That completes the cluster master and indexing tier—let's set up the clustered search environment next.

主站蜘蛛池模板: 瑞昌市| 页游| 酉阳| 新安县| 随州市| 灌南县| 桦南县| 时尚| 余庆县| 枣庄市| 二连浩特市| 太和县| 涡阳县| 仁化县| 偃师市| 天镇县| 定安县| 克什克腾旗| 翁牛特旗| 马关县| 虎林市| 黎平县| 富裕县| 来安县| 吐鲁番市| 邓州市| 阿图什市| 罗源县| 开远市| 香格里拉县| 盐山县| 舟山市| 贵港市| 唐山市| 文成县| 郁南县| 亚东县| 贵定县| 老河口市| 从化市| 呼伦贝尔市|