3.3.3 splunk forward
#选择版本
https://www.splunk.com/page/previous_releases/universalforwarder
#使用的版本8.1.3
https://download.splunk.com/products/universalforwarder/releases/8.1.3/linux/splunkforwarder-8.1.3-63079c59e632-linux-2.6-x86_64.rpm[root@wazuh-manager ~]# rpm -ivh splunkforwarder-8.1.3-63079c59e632-linux-2.6-x86_64.rpm
warning: splunkforwarder-8.1.3-63079c59e632-linux-2.6-x86_64.rpm: Header V4 RSA/SHA256 Signature, key ID b3cd4420: NOKEY
Preparing... ################################# [100%]
useradd: cannot create directory /opt/splunkforwarder
Updating / installing...
1:splunkforwarder-8.1.3-63079c59e63################################# [100%]
cp: cannot stat ‘/opt/splunkforwarder/etc/regid.2001-12.com.splunk-UniversalForwarder.swidtag’: No such file or directory
complete[root@wazuh-manager ~]# cp /opt/splunkforwarder/swidtag/splunk-UniversalForwarder-primary.swidtag /usr/share/regid.2001-12.com.splunk/
[root@wazuh-manager ~]# chown splunk:splunk /usr/share/regid.2001-12.com.splunk/splunk-UniversalForwarder-primary.swidtag [wazuh]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = json
KV_MODE = none
NO_BINARY_CHECK = true
category = Application
disabled = false
pulldown_type = true最后更新于