Splunk® App for Unix and Linux

Install and Use the Splunk App for Unix and Linux

Acrobat logo Download manual as PDF

On March 13, 2022, the Splunk App for Unix and Linux will reach its end of life. After this date, Splunk will no longer maintain or develop this product. The functionality in this app is migrating to a content pack in Data Integrations. Learn about the Content Pack for Unix Dashboards and Reports.
Acrobat logo Download topic as PDF

Log in and get started

This topic shows you how to log in to Splunk Web, access the Splunk App for Unix and Linux, and get started.

Log in to Splunk Web

To log into Splunk Web and access the Splunk App for Unix and Linux, navigate to:


Use the host and port you chose during installation of Splunk. The default port is 8000.

The first time you log in to Splunk, the default login details are:
Username - admin
Password - changeme

Splunk recommends that you change the admin password to a secure password.

Access the Splunk App for Unix and Linux

Once you've logged in to Splunk Web, the version of Splunk that is running determines exactly what you see.

In Splunk 5 and earlier, you see Splunk Home, with "Welcome" and "Home" tabs. Click on the "Home" tab to see the list of apps that are currently installed. You should see the Search and Getting Started apps, as well as the Splunk App for Unix and Linux. To access the Splunk App for Unix and Linux, click on it in the list.

In Splunk 6 and later, the Home page also displays by default, but installed apps appear in the screen; there is no need to access a menu to see them. Click on "Splunk App for Unix and Linux" in the list. You can also access the Splunk Add-on for Unix and Linux in this way, but the add-on only has a configuration page.

Important: When starting the app for the first time, you will initially be presented with a dialog box requesting that you configure the app. Read "First-time configuration" to learn about how to enable the app's inputs.

To learn about the various dashboards available, review "Dashboard reference."

Last modified on 16 November, 2016
Enable data and scripted inputs
Configure the Splunk App for Unix and Linux

This documentation applies to the following versions of Splunk® App for Unix and Linux: 5.2.2, 5.2.3, 5.2.4, 5.2.5, 6.0.0, 6.0.1, 6.0.2

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters