Splunk Search

Universal Forwarder in AIX system not sending any data to splunk server, how to configure universal forwarder in AIX?

etaga
New Member

I installed and configured Universal Forwarder in AIX but it does not send data to splunk server. I configured index in splunk server and add it to Universal Forwarder (inputs.conf) but the problem continue.

Tags (1)
0 Karma

etaga
New Member

I resolved it, was necessary to activate deploy in AIX. Now I have another problem. I configured only 3 hosts like forwarders but in App > Search&Reporting > Data Summary I find more hosts, some of them are not configured like forwarders. Why is possible that one host send logs to splunk when forwarders is not configured in it?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Did you configure outputs.conf and inputs.conf? You need to make sure that:

  1. The files that you want are being monitored by Splunk (inputs.conf)
  2. The data has a path to travel to the indexers (outputs.conf)

See these references:

http://www.splunk.com/base/Documentation/latest/Admin/Inputsconf?r=splunky
http://www.splunk.com/base/Documentation/latest/Admin/Outputsconf?r=splunky

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...