官术网_书友最值得收藏!

Configuring a TCP input

On all of the indexers, you will need to configure a TCP input for receiving the forwarded internal logs from the other Splunk servers; this input can service forwarded data from universal forwarders as well:

  1. Settings | Forwarding and receiving | Configure receiving | New Receiving Port (button)
  2. Listen on this port: 9997
  3. Save

Splunk will create or append an inputs.conf file in /opt/splunk/etc/system/local/ with the following content:

[default]
host = 172.31.28.223

[splunktcp://9997]
connection_host = ip

That completes the cluster master and indexing tier—let's set up the clustered search environment next.

主站蜘蛛池模板: 榆林市| 义乌市| 拉萨市| 镇安县| 伊宁县| 巨鹿县| 合山市| 铜川市| 姚安县| 黑水县| 武冈市| 广昌县| 阿鲁科尔沁旗| 西畴县| 铜山县| 梅河口市| 龙井市| 南召县| 河东区| 和龙市| 内江市| 丹巴县| 定安县| 裕民县| 秭归县| 滦南县| 宜川县| 鹤壁市| 会昌县| 邵阳市| 三江| 东宁县| 利川市| 天气| 灵川县| 伊宁县| 光山县| 阿克陶县| 章丘市| 台北县| 嘉善县|