|
Command |
Purpose |
|---|---|
|
|
Enables the EPEL repository to access additional packages required for syslog-ng installation. |
|
|
Installs the syslog-ng service on Rocky Linux, which will receive syslog data from ESKM. |
|
|
Downloads the Splunk Universal Forwarder installation package from Splunk’s official repository. |
|
|
Installs the Splunk Universal Forwarder on the Rocky Linux syslog server. |
|
|
Starts the Splunk Universal Forwarder for the first time and prompts for creating admin credentials. |
|
|
Configures the Universal Forwarder to automatically start on system boot. |
|
|
Creates a dedicated directory to store incoming ESKM syslog logs. |
|
|
Sets correct ownership for the ESKM log directory so syslog-ng and Splunk UF can access it. |
|
|
Applies secure permissions to the ESKM log directory. |
|
|
Monitors ESKM logs in real time to verify syslog-ng is receiving events. |
|
|
Checks the running status of the Splunk Universal Forwarder service. |
|
|
Displays the list of log files currently monitored by the Universal Forwarder. |
|
|
Enables the EPEL repository to access additional packages required for syslog-ng installation. |
|
|
Installs the syslog-ng service on Rocky Linux, which will receive syslog data from ESKM. |
|
|
Downloads the Splunk Universal Forwarder installation package from Splunk’s official repository. |
|
|
Installs the Splunk Universal Forwarder on the Rocky Linux syslog server. |
|
|
Starts the Splunk Universal Forwarder for the first time and prompts for creating admin credentials. |
|
|
Configures the Universal Forwarder to automatically start on system boot. |
|
|
Creates a dedicated directory to store incoming ESKM syslog logs. |
|
|
Sets correct ownership for the ESKM log directory so syslog-ng and Splunk UF can access it. |
|
|
Applies secure permissions to the ESKM log directory. |
|
|
Monitors ESKM logs in real time to verify syslog-ng is receiving events. |
|
|
Checks the running status of the Splunk Universal Forwarder service. |
|
|
Displays the list of log files currently monitored by the Universal Forwarder. |
Splunk CLI commands