Getting Data In

Cannot figure Universal forwarder out

chrisscott1
New Member

I have done 3-4 days of research and have been striking out. Here is the process that I follow. I install the universal forwarder on our web server to monitor system logs. Below are the steps:

  1. I execute the installable msi file from cmd prompt to create the service and start the installation process.

  2. I install the UF to C:\Program Files\SplunkUniversalForwarder\

  3. I leave the deployment server blank.

  4. Now for recieiving indexer the main splunk cleint is on z8 so I ping z8 get the IP address and put that in as the host name and assign it to port 9997 which is the default port.. is this correct?

  5. I leave the SSL certificate informaiton blank,

  6. I choose local data only.

  7. I select system log and browse to the directory path for thwere the websites IIS logs are pointing and install the service.

From here I do not know what to do. Any help would be appreciated. Am I doing this right?

Tags (3)
0 Karma

FunPolice
Path Finder

Have you told the Splunk server (z8) to listen for information from a forwarder? Go to Manager - Forwarding and Receiving to turn on receiving. Make sure to download the Deployment Monitor app to keep an eye on it as well.

You can look for relevant events in the _internal index to troubleshoot - try searching

index=_internal sourcetype="splunkd"

for starters.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...