Splunk Add-on for OPC (Legacy)

Use the Splunk Add-on for OPC

Install the Splunk Add-on for OPC in a distributed deployment

Follow these steps to install the Splunk Add-on for OPC in a distributed deployment of Splunk Enterprise.

  1. Deploy a heavy forwarder.
  2. Install dependencies.
  3. Install the Splunk Add-on for OPC on your heavy forwarder.
  4. (Optional) Install the Splunk Add-on for OPC on your indexers.

The Splunk Add-on for OPC does not need to be installed on search heads.

Deploy a heavy forwarder

Install Splunk Enterprise on a server under your control and configure it as a heavy forwarder. In most deployments, this instance hosts the data ingestion management components of the add-on as well as your HTTP event collector receiver.

  1. Install a full Splunk Enterprise instance on a server under your control. See Installation instructions in the Splunk Enterprise Installation Manual.
  2. If you have not already done so, configure your indexers or indexer cluster to receive data from forwarders.
  3. Configure your Splunk Enterprise instance as a heavy forwarder by instructing it to forward data to your receivers.
    • If you are forwarding data to one or more unclustered indexes, see Set up forwarding in Forwarding Data in the Splunk Enterprise documentation.
    • If you are forwarding data to an indexer cluster, see Configure the forwarders to use indexer discovery in Managing Indexers and Clusters of Indexers in the Splunk Enterprise documentation.

Next: Install dependencies

Install dependencies

Install the required dependencies on your heavy forwarder. See Required dependencies for your data ingestion management node.

Install the Splunk Add-on for OPC on your heavy forwarder

Follow these steps to install the add-on on the heavy forwarder:

  1. Download the Splunk Add-on for OPC from Splunkbase.
  2. Log in to Splunk Enterprise as an administrator.
  3. From the Splunk Web home screen, click the gear icon next to Apps.
  4. Click Install app from file.
  5. Locate the downloaded file and click Upload.
  6. Restart Splunk Enterprise when prompted.

Next: Set up the Splunk Add-on for OPC, or, if you want to handle data ingestion separately from data ingestion management, Install the Splunk Add-on for OPC on your indexers.

Install the Splunk Add-on for OPC on your indexers

This step is optional.

If you want to handle data ingestion separately from data ingestion management, you can configure your unclustered indexers to be the HTTP event collector receivers of your OPC data. In this case, install the Splunk Add-on for OPC to your indexers. Otherwise, skip this step and go next to Set up the Splunk Add-on for OPC.

Follow these steps to install the add-on on to each unclustered indexer in your deployment.

  1. Download the Splunk Add-on for OPC from Splunkbase.
  2. Log in to the indexer as an administrator.
  3. From the Splunk Web home screen, click the gear icon next to Apps.
  4. Click Install app from file.
  5. Locate the downloaded file and click Upload.
  6. Restart Splunk Enterprise when prompted.
  7. Log in to the indexer as an administrator.
  8. From the Splunk Web home screen, click the gear icon next to Apps.
  9. Scroll down to find Splunk Add-on for OPC, and then click Edit properties.
  10. Change the radio button selection next to "Visible" to No. This prevents the data ingestion management components from being visible on your indexers. All data ingestion management occurs on your heavy forwarder.
  11. Click Save.

Next: Set up the Splunk Add-on for OPC.

Last modified on 14 June, 2019
Install the Splunk Add-on for OPC in a single-instance deployment   Set up the Splunk Add-on for OPC

This documentation applies to the following versions of Splunk Add-on for OPC (Legacy): 1.0.0, 1.0.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters