Getting Data In

Universal Forwarder

slopresto
New Member

I have multiple LAMP servers that I am looking to monitor with Splunk. I got my server setup last Friday and setup the Universal forwarder on a couple of VM's that i am using for testing. The problem is that these hosts do not show up on my server.

I am running the configs from the *nix module on my forwarder test systems and was expecting them to show up when I was viewing the os index. Unfortunately, I only see a single host.

I have verified that the forwarder is connecting to the server. A quick view of tcpdump output shows that information is being sent, but I am not sure what the server is doing with it; as the UI only shows the index server host and no others.

Am I missing something basic here?

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Usually, host= is set to FQDN in the [defaults] stanza of $SPLUNK_HOME/etc/system/local/inputs.conf. If this value is set incorrectly, Splunk could be assigning the wrong host value for your data.

This is an instance where btool can help. On your forwarders, run this command:

splunk cmd btool --debug inputs list

And look for your various inputs and see what host= is set to for them.

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...