Getting Data In

Why is the Splunk universal forwarder not pushing data to indexer?

jpbelauskas1
New Member

I recently upgraded a workstation to Win10 Enterprise. I installed the Splunk universal forwarder, however I am not collecting any data from the workstation at the indexer. I believe it has something to do with certificates, but I am not very well versed in the product. I'm afraid the documentation isn't helping much either.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

So the forwarder worked on a previous version of Windows but is not working after upgrading to Win10?

Can you check your outputs.conf under SPLUNK_HOME\etc\system\local and verify its pointing to the correct indexer(s)?

If it is, you should then go to SPLUNK_HOME\etc\var\log\splunk and open up splunkd.log and see if its complaining about anything

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...