<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to add data from universal forwarder into splunk. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327828#M60873</link>
    <description>&lt;P&gt;The Add Data screen after a universal forwarder is available to select. &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4745iC4D155D1DF8BD036/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Apr 2018 00:38:07 GMT</pubDate>
    <dc:creator>gneumann_splunk</dc:creator>
    <dc:date>2018-04-12T00:38:07Z</dc:date>
    <item>
      <title>How to add data from universal forwarder into splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327822#M60867</link>
      <description>&lt;P&gt;I have attached screenshots of my search screen and universal forwarder monitoring screen.&lt;BR /&gt;
I can find them in the forwarder monitoring screen but not in the search screen.&lt;BR /&gt;
I followed the steps from below link.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SplunkLight/7.0.3/GettingStarted/GettingdataintoSplunkLightusingLinux"&gt;http://docs.splunk.com/Documentation/SplunkLight/7.0.3/GettingStarted/GettingdataintoSplunkLightusingLinux&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I could do till step 5, but not step 6.&lt;BR /&gt;
The New button is not available in search screen.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4746i6955105129EAEA9D/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 18:20:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327822#M60867</guid>
      <dc:creator>ajindal</dc:creator>
      <dc:date>2018-04-11T18:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to add data from universal forwarder into splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327823#M60868</link>
      <description>&lt;P&gt;Whats your Splunk deployment looks like? Do you have single instance deployment (single server acting as Search Head, Indexer, deployment server) OR distributed deployment? &lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 18:50:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327823#M60868</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-04-11T18:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to add data from universal forwarder into splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327824#M60869</link>
      <description>&lt;P&gt;Splunk Light should be single instance deployment. If a distributed deployment is the goal, then upgrade to Enteprise.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 19:09:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327824#M60869</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2018-04-11T19:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to add data from universal forwarder into splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327825#M60870</link>
      <description>&lt;P&gt;Are your forwarders showing up on the Forwarder Monitoring screen, and the Forwarder Management screen?&lt;/P&gt;

&lt;P&gt;If they are, you should then be able to be able to click the &lt;STRONG&gt;Search&lt;/STRONG&gt; tab and be on the Search screen &amp;gt; click the &lt;STRONG&gt;Add Data&lt;/STRONG&gt; button (under the Data section on the right of the Search screen) &amp;gt; On the Add Data screen, click the &lt;STRONG&gt;Forward&lt;/STRONG&gt; circle/button &amp;gt; and then on the next Add Data screen, see &lt;STRONG&gt;Select Server Class&lt;/STRONG&gt; and click &lt;STRONG&gt;New&lt;/STRONG&gt;. You should then see your &lt;STRONG&gt;Available hosts&lt;/STRONG&gt; listed with hostnames of your available universal forwarders. &lt;/P&gt;

&lt;P&gt;If you are not seeing your forwarders on the Forwarder Monitoring screen and the Forwarder Management screen, then there might be a forwarder configuration issue.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 19:19:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327825#M60870</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2018-04-11T19:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to add data from universal forwarder into splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327826#M60871</link>
      <description>&lt;P&gt;I'm testing it now to make sure what I'm telling you is correct.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Apr 2018 19:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327826#M60871</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2018-04-11T19:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to add data from universal forwarder into splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327827#M60872</link>
      <description>&lt;P&gt;Hi ajindal, &lt;/P&gt;

&lt;P&gt;I confirmed Splunk Light is working correctly when adding and configuring a universal forwarder. I just went through the entire process as documented in the link I gave you, using Splunk Light 7.0.3, and Splunk Universal Forwarder 7.0.3.  Make sure that your forwarder is compatible with your Splunk Light version. &lt;/P&gt;

&lt;P&gt;To help you, I did some troubleshooting when I had issues getting a connection, so I uninstalled the forwarder and was very careful re-installing, making sure to:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Set the &lt;STRONG&gt;receiving port&lt;/STRONG&gt; in the user interface to 9997 (TCP). This can be found at &lt;STRONG&gt;Data &amp;gt; Data receiving&lt;/STRONG&gt; in the left sidebar menu.&lt;/LI&gt;
&lt;LI&gt;Added the &lt;STRONG&gt;forward-server&lt;/STRONG&gt; command. For example: &lt;STRONG&gt;./splunk add forward-server IPaddress:9997 -auth admin:changeme&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Added the &lt;STRONG&gt;deploy-poll&lt;/STRONG&gt; command. For example &lt;STRONG&gt;./splunk set deploy-poll IPaddress:8089&lt;/STRONG&gt;. Note you are giving the management port number for Splunk Light here. &lt;/LI&gt;
&lt;LI&gt;Performed a restart, for example &lt;STRONG&gt;./splunk restart&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Note:&lt;/P&gt;

&lt;P&gt;-- After installing Splunk Light, the installation files are found in the &lt;STRONG&gt;Splunk&lt;/STRONG&gt; directory, with &lt;STRONG&gt;splunk&lt;/STRONG&gt; in the bin directory.  Management port is typically 8089.&lt;/P&gt;

&lt;P&gt;-- After installing the Splunk Universal Forwarder, the installation files are found in the &lt;STRONG&gt;SplunkForwarder&lt;/STRONG&gt; directory, with &lt;STRONG&gt;splunk&lt;/STRONG&gt; in the bin directory. The management port has to be different than Splunk Light's management port of 8089 or there is a conflict, so I set the universal forwarder's management port to 8090.&lt;/P&gt;

&lt;P&gt;After the universal forwarder is installed and you perform a restart, the forwarder takes a few minutes to load. You should be able to see the forwarder on the &lt;STRONG&gt;Forwarder management&lt;/STRONG&gt; screen after the restart.  You can now add data. Click the &lt;STRONG&gt;Search tab &amp;gt; Add Data &amp;gt; Forward&lt;/STRONG&gt;.  You should see the attached &lt;STRONG&gt;add_data_universalforwarder&lt;/STRONG&gt; screen. Select a new or existing &lt;STRONG&gt;Server Class&lt;/STRONG&gt; from the &lt;STRONG&gt;Available hosts&lt;/STRONG&gt; (host name) and add a &lt;STRONG&gt;Server Class Name&lt;/STRONG&gt; if new &amp;gt; Click &lt;STRONG&gt;Next&lt;/STRONG&gt; near the top of the screen to go to the next step. &lt;/P&gt;

&lt;P&gt;To see the dashboard on the &lt;STRONG&gt;Forwarder monitoring&lt;/STRONG&gt; screen, you must go to &lt;STRONG&gt;System &amp;gt; Forwarder monitoring&lt;/STRONG&gt; in the sidebar menu and on the Forwarder monitoring screen click the box for &lt;STRONG&gt;Enable Forwarder Montoring&lt;/STRONG&gt;. It does take a few minutes to load. See my attached &lt;STRONG&gt;monitoring-screen-uf&lt;/STRONG&gt; screenshot of the Forwarder monitoring screen. &lt;/P&gt;

&lt;P&gt;I suggest you confirm that you have the ports, IP address and commands correctly installed, and with no port conflicts.&lt;/P&gt;

&lt;P&gt;Hope this helps. &lt;IMG src="https://community.splunk.com/storage/temp/238580-monitoring-screen-uf.png" alt="alt text" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:00:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327827#M60872</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2020-09-29T19:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to add data from universal forwarder into splunk.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327828#M60873</link>
      <description>&lt;P&gt;The Add Data screen after a universal forwarder is available to select. &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4745iC4D155D1DF8BD036/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Apr 2018 00:38:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-add-data-from-universal-forwarder-into-splunk/m-p/327828#M60873</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2018-04-12T00:38:07Z</dc:date>
    </item>
  </channel>
</rss>

