官术网_书友最值得收藏!

Configuring a TCP input

On all of the indexers, you will need to configure a TCP input for receiving the forwarded internal logs from the other Splunk servers; this input can service forwarded data from universal forwarders as well:

  1. Settings | Forwarding and receiving | Configure receiving | New Receiving Port (button)
  2. Listen on this port: 9997
  3. Save

Splunk will create or append an inputs.conf file in /opt/splunk/etc/system/local/ with the following content:

[default]
host = 172.31.28.223

[splunktcp://9997]
connection_host = ip

That completes the cluster master and indexing tier—let's set up the clustered search environment next.

主站蜘蛛池模板: 东至县| 高雄市| 都江堰市| 当阳市| 双桥区| 金昌市| 金昌市| 资源县| 滨州市| 海林市| 临洮县| 平昌县| 石棉县| 广德县| 金秀| 弥勒县| 浦县| 嘉荫县| 会泽县| 建宁县| 巴林左旗| 武威市| 通州市| 卢龙县| 象州县| 高邮市| 丽江市| 武安市| 仪陇县| 乳山市| 禹城市| 和林格尔县| 北票市| 大方县| 拉孜县| 赞皇县| 淮滨县| 乐至县| 和硕县| 卢氏县| 丰顺县|