Splunk® App for Unix and Linux (Legacy)

Install and Use the Splunk App for Unix and Linux

Acrobat logo Download manual as PDF


On March 13, 2022, the Splunk App for Unix and Linux will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app has migrated to a content pack in Data Integrations. Learn about the Content Pack for Unix Dashboards and Reports.The Splunk Add-on for Unix and Linux remains supported.
This documentation does not apply to the most recent version of Splunk® App for Unix and Linux (Legacy). For documentation on the most recent version, go to the latest release.
Acrobat logo Download topic as PDF

Comparison of the Splunk App for Unix and Linux components

This topic describes the difference between the Splunk App, Splunk Add-on, and Supporting Add-on for Unix and Linux.

During the course of the development of the app, Splunk customers asked us for Unix and Linux knowledge and inputs packaged separately from the Splunk Web user interface components that are present in the full app. This request was often made in order to facilitate use on light or universal forwarders, or when the primary use case for Unix and Linux data is to correlate with other data sources in an app other than Splunk for Unix and Linux.

The app, add-on, and supporting add-on share the same common knowledge and input base, and have been put into the same installation package. The add-on also comes in its own installation package.

Following is a table that compares basic features of the app and add-on:

Feature App Add-on Supporting Add-on
Has a user interface for Splunk Web Yes Setup only, on full Splunk instances only No
Provides reports/saved searches and macros to the app N/A No Yes
Can be deployed on full Splunk instances Yes Yes Yes (but must be installed with the app to function)
Can be deployed on light and universal forwarders No* (The package installs, but does not run) Yes No
Can be installed on Windows Splunk instances Yes* (All data inputs must be disabled) Yes, on search heads and indexers only (but all data inputs must be disabled) Yes* (All data inputs must be disabled)
Can provide data to other Splunk applications Yes Yes No
Last modified on 08 December, 2018
PREVIOUS
Splunk App for Unix and Linux
  NEXT
New to Splunk?

This documentation applies to the following versions of Splunk® App for Unix and Linux (Legacy): 5.2.3, 5.2.4


Was this documentation topic helpful?


You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters