Install the universal forwarder on HP-UX

Important: Splunk does not offer an installation package for Splunk Enterprise version 6.3.0 or later on HP-UX. It does, however, offer a universal forwarder installation package for HP-UX versions 11i v2 and 11i v3. These instructions detail how to install the universal forwarder on those versions of HP-UX.

To use Splunk Enterprise on HP-UX, you must download an older version of the Splunk software.

Basic install

To install the universal forwarder on an HP-UX system, expand the tar file, using GNU tar, into an appropriate directory. The default install directory is /opt/splunkforwarder.

When you install with the tar file:

  • The forwarder does not create the splunk user automatically. If you want the forwarder to run as a specific user, you must create the user manually.
  • Be sure the disk partition has enough space to hold the uncompressed volume of the data you plan to keep indexed.

Start the universal forwarder

The universal forwarder can run as any user on the local system. If you run it as a non-root user, make sure that it has the appropriate permissions to read the inputs that you specify.

To start the forwarder from the command line interface, run the following command from $SPLUNK_HOME/bin directory (where $SPLUNK_HOME is the directory into which you installed Splunk Enterprise):

 ./splunk start

By convention, this document uses:

  • $SPLUNK_HOME to identify the path to your Splunk Enterprise installation.
  • $SPLUNK_HOME/bin/ to indicate the location of the command line interface.

Configure auto-start of the forwarder

The HP-UX version of the universal forwarder does not register itself to auto-start on reboot. However, you can register it by running the following command in the $SPLUNK_HOME/bin directory in a shell prompt:

./splunk enable boot-start

Startup options

The first time you start the universal forwarder after a new installation, you must accept the license agreement. To start Splunk Enterprise and accept the license in one step:

 $SPLUNK_HOME/bin/splunk start --accept-license

Note: There are two dashes before the accept-license option.

This documentation applies to the following versions of Splunk® Enterprise: 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14

