Splunk forwarder
Last updated
Last updated
A Splunk forwarder is like a agent in Wazuh Siem. It is a piece of software the runs on a remote machine/client that sends data back to a central server
make sure the port you are using on the server to receive data is not blocked by firewall, typically it is
open a firewall port in windows:
https://ec.europa.eu/digital-building-blocks/sites/display/CEKB/How+to+open+a+port+on+the+firewall
in splunk make sure you add a receiving port under settings > forward and receiving
click add new
add what ever port you want and click save, 9997 is the default
Download the splunk forwarder. You need to have a splunk user and pass to proceed to the download link
make sure transfer or download to the client machine you want to run it
When starting the executable
check the box to except the license
for this one we select on-prem
click Customize Options
Unless you have a SSL Cert or know what it is, leave this blank
Select virtual account
Leave all this default
Select the options you want to monitor
Performance monitors with run a lot and fill up your logs
add a user and password
usually you would use the same one for multiple endpoints
If you don't have a deployment server you can skip this
this is your splunk server IP and listening port you set up in server
install
if you see this just hit OK some times it works after that other times it will start to roll back. If it has rolled back restart the computer and try again.
if successful you are good