splunk and splunk forwarder installation
create a group and account for splunk user
---------------------------------------
/usr/sbin/groupadd -g 9991 splunk
/usr/sbin/adduser -c "Splunk" -u 9991 -g 9991 -s /bin/bash -d /opt/splunk -m splunk
cp -r /etc/skel/ /opt/splunk
chown -R splunk:splunk /opt/splunk/
set the limit for the splunk
---------------------------------------
vi /etc/security/limits.d/99-mrll-splunk.conf
splunk hard nofile 20240
splunk soft nofile 10240
splunk hard nproc 10240
splunk soft nproc 2048
Set the environment path for the splunk home directory
echo "# The btool command does not have the right LD_LIBRARY_PATH...
LD_LIBRARY_PATH=:/opt/splunk/lib
export LD_LIBRARY_PATH
# also set the splunk home for the application
SPLUNK_HOME=/opt/splunk
export SPLUNK_HOME
# and set the path for the user
PATH=${PATH}:/opt/splunk/bin
export PATH
" >> /opt/splunk/.bashrc
Install the splunk
rpm -ivh splunk-6.5.2-67571ef4b87d-linux-2.6-x86_64.rpm
su - splunk -c '/opt/splunk/bin/splunk start --accept-license --answer-yes'
sudo /opt/splunk/bin/splunk enable boot-start -user splunk --accept-license --answer-yes
Install the splunk forwarder
rpm -ivh splunkforwarder-6.5.2-67571ef4b87d-linux-2.6-x86_64.rpm
su - splunk -c '/opt/splunkforwarder/bin/splunk start --accept-license --answer-yes'
/opt/splunkforwarder/bin/splunk enable boot-start -user splunk --accept-license --answer-yes
create a group and account for splunk user
---------------------------------------
/usr/sbin/groupadd -g 9991 splunk
/usr/sbin/adduser -c "Splunk" -u 9991 -g 9991 -s /bin/bash -d /opt/splunk -m splunk
cp -r /etc/skel/ /opt/splunk
chown -R splunk:splunk /opt/splunk/
set the limit for the splunk
---------------------------------------
vi /etc/security/limits.d/99-mrll-splunk.conf
splunk hard nofile 20240
splunk soft nofile 10240
splunk hard nproc 10240
splunk soft nproc 2048
Set the environment path for the splunk home directory
echo "# The btool command does not have the right LD_LIBRARY_PATH...
LD_LIBRARY_PATH=:/opt/splunk/lib
export LD_LIBRARY_PATH
# also set the splunk home for the application
SPLUNK_HOME=/opt/splunk
export SPLUNK_HOME
# and set the path for the user
PATH=${PATH}:/opt/splunk/bin
export PATH
" >> /opt/splunk/.bashrc
Install the splunk
rpm -ivh splunk-6.5.2-67571ef4b87d-linux-2.6-x86_64.rpm
su - splunk -c '/opt/splunk/bin/splunk start --accept-license --answer-yes'
sudo /opt/splunk/bin/splunk enable boot-start -user splunk --accept-license --answer-yes
Install the splunk forwarder
rpm -ivh splunkforwarder-6.5.2-67571ef4b87d-linux-2.6-x86_64.rpm
su - splunk -c '/opt/splunkforwarder/bin/splunk start --accept-license --answer-yes'
/opt/splunkforwarder/bin/splunk enable boot-start -user splunk --accept-license --answer-yes
Comments
Post a Comment