Getting Data In

Why is my forwarder missing from the list of forwarders?

Hekmel
Engager

I have installed universal forwarders on all of the servers I want to monitor with Splunk. If I go on the Splunk Server to "Settings" -> "Add Data" -> "Forward" I find all but one of the servers in that list. Lets call the server serverx

If I go from the Splunk dashboard to "Search and Reporting" and search for that server that is missing in the forwarders list I find information on it. host=serverx

Is there some way that I can get serverx into the list of forwareders so I can define monitoring parameters for the hosts? Or is there another way of doing this all together?

0 Karma
1 Solution

Hekmel
Engager

Thank you all for suggestions. We ended up adding all the servers via the Linux shell to an application and then it worked regardless if we still cannot select the host from the gui for anything.

View solution in original post

Hekmel
Engager

Thank you all for suggestions. We ended up adding all the servers via the Linux shell to an application and then it worked regardless if we still cannot select the host from the gui for anything.

hardikJsheth
Motivator

Can you check if you have deploymentclient.conf file on your UF? If this file is not present, that means the setup to deployment server is missing and you can refer the link provided by @garethatiag.

In case the file is present check the port connectivity between deployment server and UF. Deployment server requires bidrectional connection between UF and Deployment server for the management port (mostly it's 8089).

ddrillic
Ultra Champion

You can administer the forwarders from two services, the Forwarder management and the Monitoring Console -

alt text

gjanders
SplunkTrust
SplunkTrust

I'm not completely clear on the issue from your description, but it sounds like you might be having an issue with configuring a universal forwarder to talk to the deployment server?
If so then the configure deployment clients documentation might help

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...