<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Install Splunk UF in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537731#M7131</link>
    <description>&lt;P&gt;here is what is in the outputs.conf file in the /etc/system/local&lt;/P&gt;&lt;P&gt;[tcpout]&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;defaultGroup = default-autolb-group&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;server = x.x.x.103:9997&lt;/P&gt;&lt;P&gt;[tcpout-server://x.x.xx.103:9997]&lt;/P&gt;</description>
    <pubDate>Thu, 28 Jan 2021 21:34:21 GMT</pubDate>
    <dc:creator>molinarf</dc:creator>
    <dc:date>2021-01-28T21:34:21Z</dc:date>
    <item>
      <title>How to install Splunk Universal Forwarder on a Linux server?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537109#M7100</link>
      <description>&lt;P&gt;I know this was probably answered before, but I am not able to find any answers...&lt;/P&gt;
&lt;P&gt;I am trying to install the Splunk UF on a Linux server after having to manually uninstall it because of overlapping 7.2.3 (.tgz) and 8.1.0 (.rpm) packages. I am trying to install the 8.1.0 rpm but get the error that it is already installed. When I try to uninstall it since the error says it's installed, then it says that it is already installed. I can't reboot the server because of operations, but would like to have Splunk operational and reporting to the indexer. Can anyone help with guidance on how to overcome this error?&lt;/P&gt;
&lt;P&gt;Thank you for any assistance that can be provided.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 05:40:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537109#M7100</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-27T05:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537123#M7102</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/211605"&gt;@molinarf&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Did you try upgrading with "rpm -U" ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:00:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537123#M7102</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-25T21:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537131#M7103</link>
      <description>&lt;P&gt;That doesn't work... It thinks that it is already installed and I can't uninstall it either. I am finding that the only option is to install a version that wasn't previously installed and see how that goes. If it fails, then I will have to submit a case.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jan 2021 21:32:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537131#M7103</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-25T21:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537160#M7105</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/211605"&gt;@molinarf&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;try tar!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 07:40:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537160#M7105</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-26T07:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537302#M7108</link>
      <description>Are you log in as root or use sudo?&lt;BR /&gt;What rpm -qi splunk\* shows?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Tue, 26 Jan 2021 20:58:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537302#M7108</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-01-26T20:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537305#M7109</link>
      <description>&lt;P&gt;After running the command&amp;nbsp; 'rpm -qi splunk\* ', the response was&lt;/P&gt;&lt;P&gt;package splunk is not installed.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:06:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537305#M7109</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-26T21:06:53Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537309#M7110</link>
      <description>Can you try also rpm -qa | egrep splunk and if it found splunk&amp;lt;something&amp;gt; (splunkforwarder....) then it is installed otherwise probably not via rpm. Also put could try rpm -qif /opt/splunkforwarder/bin/splunk or where ever it has installed.&lt;BR /&gt;And how about the user id which you are using?</description>
      <pubDate>Tue, 26 Jan 2021 21:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537309#M7110</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-01-26T21:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537311#M7111</link>
      <description>&lt;P&gt;I had a similar problem to this in the past, and if I remember correctly I downloaded the tgz file and did:&lt;/P&gt;&lt;P&gt;sudo tar xvzf /tmp/splunk.tgz -C /opt&lt;/P&gt;&lt;P&gt;This overwrote, and I was able to do "splunk disable boot-start", etc...&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537311#M7111</guid>
      <dc:creator>gordo32</dc:creator>
      <dc:date>2021-01-26T21:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537318#M7112</link>
      <description>&lt;P&gt;Here is the results:&lt;/P&gt;&lt;P&gt;rpm -qa | egrep splunk&lt;/P&gt;&lt;P&gt;splunkforwarder-8.1.1-08187535c166.x86_64&lt;/P&gt;&lt;P&gt;rpm -qif /opt/splunkforwarder/bin/splunk&lt;/P&gt;&lt;P&gt;Name: splunkforwarder&lt;/P&gt;&lt;P&gt;Version: 8.1.1&lt;/P&gt;&lt;P&gt;Release: 8.1.1-08187535c166&lt;/P&gt;&lt;P&gt;etc.....&lt;/P&gt;&lt;P&gt;If these commands show that it is installed, why then when I try to do an uninstall to clean up, it tells me it is not installed. Of course, that is why when I try to reinstall, I get the it is already installed.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:36:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537318#M7112</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-26T21:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537319#M7113</link>
      <description>&lt;P&gt;I had done splunk disable boot-start before I uninstalled. The problem was that there was the .tgz and .rpm both installed at the same time. I am trying to clean it up, so that I can properly reinstall. Thanks for the suggestion.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jan 2021 21:38:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537319#M7113</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-26T21:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537356#M7114</link>
      <description>&lt;P&gt;Yes this means that this package is already installed.&lt;/P&gt;&lt;P&gt;Currently better way to install/update it is use yum instead of rpm or def on redhat 8+ versions.&lt;/P&gt;&lt;P&gt;As it it already installed you should do:&lt;/P&gt;&lt;P&gt;sudo yum update ./&lt;SPAN&gt;splunkforwarder-8.x.y-xxxx &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;where x and/or y is&amp;nbsp;&lt;/SPAN&gt;greater than 1 and 1.&lt;/P&gt;&lt;P&gt;If you are still using old os and use rpm then the correct way is&amp;nbsp;&lt;/P&gt;&lt;P&gt;sudo rpm -Uvh --replacepkgs (or --force)&amp;nbsp;./&lt;SPAN&gt;splunkforwarder-8.x.y-xxxx.rpm&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;man rpm on that box or google will help you more.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 07:17:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537356#M7114</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-01-27T07:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537485#M7117</link>
      <description>&lt;P&gt;I ran the following command as you suggested.&lt;/P&gt;&lt;P&gt;sudo rpm -Uvh --replacepkgs (or --force) ./splunkforwarder-8.x.y-xxxx.rpm&lt;/P&gt;&lt;P&gt;It seemed to install fine, but it never reported into the indexer. I did some poking around in man rpm and decided to run&lt;/P&gt;&lt;P&gt;rpm -evv --test splunkforwarder-8.x.y-xxxx.rpm&lt;/P&gt;&lt;P&gt;What returned looked like it would uninstall fine. I checked the splunkd.log to see if there was any indications or error related to the installation or in fact anything and I found none, so my assumption is that everything is supposed to be okay. My next step was to stop splunk and then uninstall. I ran the uninstall command from /opt/splunkforwarder/bin since I was there&lt;/P&gt;&lt;P&gt;rpm -e splunkforwarder-8.x.y-xxxx.rpm&lt;/P&gt;&lt;P&gt;I received the following message: Warning: file /opt/splunkforwarder/ftr: remove failed: no such file or directory. I guess I was in the wrong directory so I reran the command from /opt and this error appeared&lt;/P&gt;&lt;P&gt;Error returned "package splunkforwarder-8.x.y-xxxx.rpm is not installed.&amp;nbsp; Anyway, I looked in the directory and the splunkforwarder directory was there. I checked it and found only etc and var was there. So I am not sure if it would be prudent for me to remove the splunk forwarder directory and reinstall, like maybe using tar splunkforwarder-8.x.y-xxxx.tgz? I look forward to your response. Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jan 2021 19:17:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537485#M7117</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-27T19:17:08Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537620#M7119</link>
      <description>&lt;P&gt;When you are removing package, don't use .rpm on name, just package name and if needed version etc. Also don't be on a directory which belongs to package when you are trying to remove it. It usually try to remove that directory too.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.tecmint.com/20-practical-examples-of-rpm-commands-in-linux/" target="_blank"&gt;https://www.tecmint.com/20-practical-examples-of-rpm-commands-in-linux/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;And always use sudo rpm or first switch to user root.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope that these instructions helps you.&lt;/P&gt;&lt;P&gt;And finally don't install with tar until you have removed package with rpm, otherwise you have invalid rpm db catalog on your host and it will generate later other issues!&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 13:59:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537620#M7119</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-01-28T13:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537663#M7120</link>
      <description>&lt;P&gt;Per Support, I did do the installation using the tar file&lt;/P&gt;&lt;P&gt;sudo tar xvzf /tmp/splunk.tgz&lt;/P&gt;&lt;P&gt;Splunk is there, just like when I do the .rpm. The problem I am faced with is that it isn't communicating with the indexer. I may have to just remove the UF all together until that server is rebuilt.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 17:00:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537663#M7120</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-28T17:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537666#M7121</link>
      <description>&lt;P&gt;I did try that too. Even when I do the rpm -e splunk8.x.y... it still told me that it was not installed. Support had me do the install with the tar file. I now have the UF installed, but the problem now is that the it is not communicating with the indexer.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 17:05:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537666#M7121</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-28T17:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537682#M7122</link>
      <description>Have you create outputs.conf or app which define where your indexer(s) is/are?or hav you add DS information to this UF?</description>
      <pubDate>Thu, 28 Jan 2021 18:17:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537682#M7122</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-01-28T18:17:16Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537687#M7123</link>
      <description>&lt;P&gt;There is an outputs.conf file which is showing that there is an indexer and listening on port 9997, but it is showing as inactive. There is no DS (Deployment server) that is listed.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 18:36:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537687#M7123</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-28T18:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537690#M7124</link>
      <description>What you are seeing on UF’s splunkd.log and metrics.log?</description>
      <pubDate>Thu, 28 Jan 2021 18:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537690#M7124</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-01-28T18:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537697#M7125</link>
      <description>&lt;P&gt;splunkd.log shows that everything seems to be working fine. In the metrics log, it seems that there is nothing collected and sent, but not really sure about it. I did find that there is this line that makes it seem that it is trying to communicate with the indexer and DS.&lt;/P&gt;&lt;P&gt;INFO StatusMgr - destHost=&amp;lt;ip&amp;gt;, destIp=&amp;lt;ip&amp;gt;, destPort=9997, eventType=connect_try,&amp;nbsp; publisher=Tcpout, sourcePort=8089, statusee=TCPOutputProcessor&lt;/P&gt;&lt;P&gt;INFO StatusMgr - destHost=&amp;lt;ip&amp;gt;, destIp=&amp;lt;ip&amp;gt;, destPort=9997, eventType=connect_fail,&amp;nbsp; publisher=Tcpout, sourcePort=8089, statusee=TCPOutputProcessor&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 19:11:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537697#M7125</guid>
      <dc:creator>molinarf</dc:creator>
      <dc:date>2021-01-28T19:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: Install Splunk UF</title>
      <link>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537710#M7126</link>
      <description>It tried and fail. Usually the reason can found front splunkd.log on UF and/or Indexer.&lt;BR /&gt;Also curl or tcpdump from cmd line can used to check why it fails.</description>
      <pubDate>Thu, 28 Jan 2021 20:16:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-install-Splunk-Universal-Forwarder-on-a-Linux-server/m-p/537710#M7126</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-01-28T20:16:54Z</dc:date>
    </item>
  </channel>
</rss>

