Since much of the data you will ingest into Splunk will likely come from the logs of application and web servers, we'll need to install a universal forwarder on a server and configure it to monitor specific logs and send that data to Splunk for indexing, along with some configuration settings that tell Splunk how to parse the logs and which index to store the data in.
Installing Splunk universal forwarder
Installation steps
The Splunk universal forwarder is basically a specialized instance of Splunk Enterprise with most features disabled, and it is a separate binary, but you can follow the same process as was used for installing Splunk Enterprise in Chapter 3, Installing and Configuring Splunk, for both Linux and Windows...