In this and the following chapter, you will learn how to administer your Splunk deployment, starting with getting data into Splunk. In this context, the term administration includes a wide range of initial setup as well as the day-to-day tasks involved in getting data into Splunk, properly parsed and indexed; managing the indexing and search head clusters so that the data can be searched, deploying Splunk apps, and setting up users and their roles so that they can access the data.
The topics covered in this chapter include the following:
- Installing and configuring universal forwarders to send log data to Splunk
- Setting up a heavy forwarder
- Configuring inputs from other types of data sources
- How to configure an HTTP Event Collector (HEC) to input data
- How to configure Splunk to properly parse nonstandard data formats
- How to distribute configuration files...