Public server setup
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Public server setup
- After installing the Splunk Server, edit $SPLUNK_HOME/etc/myinstall/search.xml to add this line.
<isReadonly>True</isReadonly>
- Restart the server.
# splunk restart
- Test the setup
- Click Add data input on the right-hand side of Splunk's home page.
- Find the row for Files and Directories and click Add input at the right hand side of the page.
- Try to add /etc/passwd as a Tail input to make sure that you can't. Because if you don't try this, someone else will!
This documentation applies to the following versions of Splunk: 2.1 , 2.2 , 2.2.1 , 2.2.3 , 2.2.6 View the Article History for its revisions.