今天实验增加一个forwarder ,并且配置在deployment server 上,而且还有可以在search head 上查询到数据。
1:install universal forwarder:
docker run --network skynet --name fd02 --hostname fd02 -e "SPLUNK_PASSWORD=sheng2020" -e "SPLUNK_START_ARGS=--accept-license" -e "SPLUNK_STANDALONE_URL=fd01" -it splunk/universalforwarder:latest
2: 检查和deploy-server 的连接:
splunk list forward-server
[root@fd02 splunkforwarder]# splunk list forward-server
Active forwards:
fd01:9997
Configured but inactive forwards:
None