官术网_书友最值得收藏!

Configuring a TCP input

On all of the indexers, you will need to configure a TCP input for receiving the forwarded internal logs from the other Splunk servers; this input can service forwarded data from universal forwarders as well:

  1. Settings | Forwarding and receiving | Configure receiving | New Receiving Port (button)
  2. Listen on this port: 9997
  3. Save

Splunk will create or append an inputs.conf file in /opt/splunk/etc/system/local/ with the following content:

[default]
host = 172.31.28.223

[splunktcp://9997]
connection_host = ip

That completes the cluster master and indexing tier—let's set up the clustered search environment next.

主站蜘蛛池模板: 工布江达县| 汝阳县| 深圳市| 裕民县| 南华县| 枣庄市| 木里| 鱼台县| 咸阳市| 四平市| 商城县| 大兴区| 丽江市| 舒城县| 电白县| 安顺市| 涿州市| 怀远县| 清远市| 冀州市| 林州市| 西安市| 田东县| 登封市| 峨眉山市| 清水河县| 锡林郭勒盟| 图们市| 策勒县| 怀宁县| 临邑县| 泸溪县| 内黄县| 柳河县| 榕江县| 剑川县| 土默特右旗| 沙田区| 忻州市| 泰宁县| 晋州市|