<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Linux Forwarder Shows up Monitor, but Can't add data to Splunk Cloud? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Linux-Forwarder-Shows-up-Monitor-but-Can-t-add-data-to-Splunk/m-p/488767#M83642</link>
    <description>&lt;P&gt;Did you enable to configuration ? Read through the "Enable the data and scripted inputs with configuration files" section in the below link.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Enabledataandscriptedinputs"&gt;https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Enabledataandscriptedinputs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Note on the install, you also need it on the Search Head and Indexers. You may need to raise a Splunk Support ticket for this&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Install"&gt;https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Install&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Mar 2020 05:46:29 GMT</pubDate>
    <dc:creator>anmolpatel</dc:creator>
    <dc:date>2020-03-09T05:46:29Z</dc:date>
    <item>
      <title>Linux Forwarder Shows up Monitor, but Can't add data to Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Linux-Forwarder-Shows-up-Monitor-but-Can-t-add-data-to-Splunk/m-p/488766#M83641</link>
      <description>&lt;P&gt;I have installed a universal-forwarder on a Ubuntu Linux box without error, here is some validation:&lt;/P&gt;

&lt;P&gt;Splunk list forward-server&lt;BR /&gt;
Active forwards:&lt;BR /&gt;
    input-prd-p-xxxxxxxxxx.cloud.splunk.com:9997 (ssl)&lt;/P&gt;

&lt;P&gt;The forward does show up in monitor, but when I get to add the Forwarder under Settings -&amp;gt; Data. It doesn't show any forwarders available and show the refresh button.  I did also download and copy Splunk for Linux under /opt/splunkforwarder/etc/apps/Splunk_TA_linux as first goal is to get performance data into the cloud. &lt;/P&gt;

&lt;P&gt;Thank You!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:31:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Linux-Forwarder-Shows-up-Monitor-but-Can-t-add-data-to-Splunk/m-p/488766#M83641</guid>
      <dc:creator>cjwallac35</dc:creator>
      <dc:date>2020-09-30T04:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Linux Forwarder Shows up Monitor, but Can't add data to Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Linux-Forwarder-Shows-up-Monitor-but-Can-t-add-data-to-Splunk/m-p/488767#M83642</link>
      <description>&lt;P&gt;Did you enable to configuration ? Read through the "Enable the data and scripted inputs with configuration files" section in the below link.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Enabledataandscriptedinputs"&gt;https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Enabledataandscriptedinputs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Note on the install, you also need it on the Search Head and Indexers. You may need to raise a Splunk Support ticket for this&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Install"&gt;https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Install&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 05:46:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Linux-Forwarder-Shows-up-Monitor-but-Can-t-add-data-to-Splunk/m-p/488767#M83642</guid>
      <dc:creator>anmolpatel</dc:creator>
      <dc:date>2020-03-09T05:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Linux Forwarder Shows up Monitor, but Can't add data to Splunk Cloud?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Linux-Forwarder-Shows-up-Monitor-but-Can-t-add-data-to-Splunk/m-p/488768#M83643</link>
      <description>&lt;P&gt;Thank You for your reply!&lt;/P&gt;

&lt;P&gt;There is no $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local directory there is a $SPLUNK_HOME/etc/apps/Splunk_TA_linux /default directory. There also is no existing input.conf file, the files available in $SPLUNK_HOME/etc/apps/Splunk_TA_linux /default are:&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/etc/apps/Splunk_TA_linux/default$ ls -ltr&lt;BR /&gt;
total 52&lt;BR /&gt;
-rw-r--r-- 1 splunk splunk  2833 Apr 19  2018 transforms.conf&lt;BR /&gt;
-rw-r--r-- 1 splunk splunk  1481 Apr 19  2018 tags.conf&lt;BR /&gt;
-rw-r--r-- 1 splunk splunk  7821 Apr 19  2018 props.conf&lt;BR /&gt;
-rw-r--r-- 1 splunk splunk  2802 Apr 19  2018 eventtypes.conf&lt;BR /&gt;
-rw-r--r-- 1 splunk splunk 24647 Apr 19  2018 eventgen.conf&lt;BR /&gt;
drwxr-xr-x 3 splunk splunk    16 Apr 19  2018 data&lt;BR /&gt;
-rw-r--r-- 1 splunk splunk   457 Apr 19  2018 app.conf&lt;/P&gt;

&lt;P&gt;This is Splunk_TA_linux which in my understanding is different then Splunk Add-on for Unix and Linux, I used Splunk_TA_linux because it didn't require logging a support ticket.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:31:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Linux-Forwarder-Shows-up-Monitor-but-Can-t-add-data-to-Splunk/m-p/488768#M83643</guid>
      <dc:creator>cjwallac35</dc:creator>
      <dc:date>2020-09-30T04:31:12Z</dc:date>
    </item>
  </channel>
</rss>

