Install an ASGER APP on search head, indexer, forwarder or single instance Splunk server.
There are three ways to install the ASGER App:
Install from Splunk web UI: Manage Apps->Browse more apps->Search keyword “ASGER” and find the app ->Click “Install free” button->Click restart splunk service.
Install from file on Splunk web UI: Manage Apps->Install from file->Upload the .tgz file which is downloaded from https://splunkbase.splunk.com/app/6452/ ->check the upgrade box-> click restart splunk service.
Install from file on Splunk server CLI interface: Extract the .tgz file->Place the asger folder under $SPLUNK_HOME/etc/apps-> Restart Splunk service.
Add data input:
1- Settings->Data Input->UDP
2- Port: 1514 (Example)
3- Sourcetype: asger_log
4- App Context: SOBE ASGER App For Splunk(asger)
5- Create Index with name: "asger"
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.