i have installed the template Citrix XenDesktop7
On my Broker i have installed the SplunkUniversialForwarder and the template i have copied directly in the path from the forwarder.
C:\Program Files\SplunkUniversalForwarder
But i get any data. the log /var/log tell me no error messages.
Can anybody tell whats wrong?
There are a few things to check:
We were working through this Saturday, but it seems he's getting a permission issue with calling the powershell scripts. I'm wondering if when configuring Splunk to run as this account, the account doesn't have access on the local machine to call the powershell scripts.
The account needs to be a local administrator and a Citrix admin. Also, I forgot to mention that you need to set the PowerShell execution policy to RemoteSigned at a minimum. Try running the PowerShell scripts directly from the console as well to get more information.
To be clear, do you have the app placed in C:\Program Files\SplunkUniversalForwarder\etc\apps\ ?
Also, it looks like this app contains add-ons for the universal forwarders - they're in appserver/addons. These are the ones that should be placed and configured in etc/apps.
You'll need to make sure indexes.conf with the indexes for this app are configured on your Splunk indexer before you'll receive data.
Also, you'll need to make sure outputs.conf is configured to send to your Splunk instance.
hello,
please see the picture
I am an absolute beginner in splunk
I did everything as instructed but nothing happens 😞
Do I have something to adjust in splunk the app to feed with data?,Hello,
please see the picture
I am an absolute beginner in splunk
I did everything as instructed but nothing happens 😞
Do I have something to adjust in splunk the app to feed with data?