Getting Data In

How to configure Universal Forwarder on my personal machine where Splunk Enterprise is installed for learning purpose?

ashishmaind2499
New Member

I installed Splunk Universal Fwd and Splunk Enterprise on my C drive. I created a sample file and modified the inputs.conf as mentioned in one of the ans(link given below) and enabled the receiver by setting port to 9997. Do we have to modify/create outputs.conf file? I tried creating outputs.conf too..but no use. In outputs.conf I gave the server name as localhost and port as 9997. Am I missing something? Also, do we have to modify anything in distributed search? I assume my Splunk Enterprise is acting both as SH and Indexer.
Have referred to below ans but didnt got the answer
https://answers.splunk.com/answers/490343/how-to-properly-configure-universal-forwarder-loca.html#an...

0 Karma

jkat54
SplunkTrust
SplunkTrust

Please share your inputs.conf and outputs.conf.

Also check if firewall is blocking any ports please.

0 Karma

xpac
SplunkTrust
SplunkTrust

If you're running both on the same system, you might run into trouble because, by default, both want to listen on TCP 9997.
Check if both instances actually run, you might have to change the splunkd port of the UF using server.conf.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...