Getting Data In

how can i get the data from my Pc windows to my splunk entreprise running on linux fedora25

sekeita
New Member

I install spunk enterprise on fedora server on virtual server(VM12 pro) and I try to get the data in ,then I install the forwarder on my PC for monitor Somme folder but it still no working, please can you help me to get the data in my spunk enterprise just for learning purpose

Tags (1)
0 Karma
1 Solution

Richfez
SplunkTrust
SplunkTrust

There's a full set of documentation for how to forward data at docs.splunk.com.

It will walk you through a checklist, which is that you need to
a) Configure receiving on your indexer
b) Install the UF (which you've done)
c) Configure the UF to forward data to that indexer's receiving port
d) Configure the UF to actually collect and send in data.

A) is done on the Splunk server in settings/Forwarding and Receiving.
B) You've done.
C) Should have been done at install of the UF. If not, it's easy enough to add later with the add forwarder-server command.

If you could go through that, it explains things in more detail than I could here. It'll take a bit of reading, but if you get stuck ask back here again, we can help with specific problems really well!

Happy Splunking,
Rich

View solution in original post

0 Karma

Richfez
SplunkTrust
SplunkTrust

There's a full set of documentation for how to forward data at docs.splunk.com.

It will walk you through a checklist, which is that you need to
a) Configure receiving on your indexer
b) Install the UF (which you've done)
c) Configure the UF to forward data to that indexer's receiving port
d) Configure the UF to actually collect and send in data.

A) is done on the Splunk server in settings/Forwarding and Receiving.
B) You've done.
C) Should have been done at install of the UF. If not, it's easy enough to add later with the add forwarder-server command.

If you could go through that, it explains things in more detail than I could here. It'll take a bit of reading, but if you get stuck ask back here again, we can help with specific problems really well!

Happy Splunking,
Rich

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...