Getting Data In

Cannot figure Universal forwarder out

chrisscott1
New Member

I have done 3-4 days of research and have been striking out. Here is the process that I follow. I install the universal forwarder on our web server to monitor system logs. Below are the steps:

  1. I execute the installable msi file from cmd prompt to create the service and start the installation process.

  2. I install the UF to C:\Program Files\SplunkUniversalForwarder\

  3. I leave the deployment server blank.

  4. Now for recieiving indexer the main splunk cleint is on z8 so I ping z8 get the IP address and put that in as the host name and assign it to port 9997 which is the default port.. is this correct?

  5. I leave the SSL certificate informaiton blank,

  6. I choose local data only.

  7. I select system log and browse to the directory path for thwere the websites IIS logs are pointing and install the service.

From here I do not know what to do. Any help would be appreciated. Am I doing this right?

Tags (3)
0 Karma

FunPolice
Path Finder

Have you told the Splunk server (z8) to listen for information from a forwarder? Go to Manager - Forwarding and Receiving to turn on receiving. Make sure to download the Deployment Monitor app to keep an eye on it as well.

You can look for relevant events in the _internal index to troubleshoot - try searching

index=_internal sourcetype="splunkd"

for starters.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...