Hi all
I have installed the splunk light on Host have IP 10.1.1.2 and I have installed the universal forwarder on user have IP 10.1.1.10 ,
when I installed the UF it's asked me the host of deployment server and receiving , I put the deployment server is the same IP of Host 10.56.1.2 and the receiving is also the same , is that correct . if not what will be the deployment server is ? and what the content of it ?
then , i opened the main interface of splunk to add data , but it's told me that there are currently no forwarder configured as deployment client , see the attached image
what can i do ?
.
What command you use to configure deployment server and receiver ?
If you didn't set up a deployment server then you should leave that part of the forwarder configuration empty and fill in the receiving field, instead.
Once you've done that, you must enable receiving in the Splunk server on 10.1.1.2. Go to Settings->Forwarding and Receiving and click "Add new" on the Receiving line. Fill in the form and click Save to receive data from your forwarder.
That screen shot is from the Forwarder Management page, which is only useful on a Deployment Server (DS). You don't have a DS, so that page is not useful to you.
To find your data, go to the Search & Reporting app and search for "host=".