Deployment Architecture

not getting universal forwarder to load up correctly

jchilovich
New Member

I'm completely confused.
After reading thru the many Q/A on universal forwarder and installing on WAS, didn't help
I want the Universal forwarder on a WAS box to send to Indexer on UNIX box. I loaded UF followed by Splunk Forwarder Add-on for WAS all on the WAS box.

1) Do I have to have a full Splunk instance initially?

2) if not, from what directory do I install (unpack the tar file) for the Add-on portion? somehow I have 3 directories a) splunk, b)splunk_forwarder_addon_was, c)splunkforwarder. this is confusing the heck out of me.

3) Seems that the forwarder defaults to port 8089 and not 8000. I think I can work around that based on what I've read. Just need to get past everything else.

PLEASE HELP

Tags (2)
0 Karma

jchilovich
New Member

Thanks for the response.
yes, ran the jar file to create the outputs.conf file and was able to get data sent to indexer instance. my question is more directed to if needing a full Splunk instance on the WAS server before I loaded the Universal Forwarder. I think I have my answer since I tried both with/without.
I got confused on the directories that the Forwarder and the Forwarder Add-on created. I loaded the forwarder Add-on & the Appliance add-on under 'apps' directory '/splunkforwarder/etc/apps' which I'm assuming was the correct way to go.

0 Karma

jchilovich
New Member

Thanks for the response.
yes, ran the jar file to create the outputs.conf file and was able to get data sent to indexer instance. my question is more directed to if needing a full Splunk instance on the WAS server before I loaded the Universal Forwarder. I think I have my answer since I tried both with/without.
I got confused on the directories that the Forwarder and the Forwarder Add-on created. I loaded the forwarder Add-on & the Appliance add-on under 'apps' directory '/splunkforwarder/etc/apps' which I'm assuming was the correct way to go.

0 Karma

starcher
SplunkTrust
SplunkTrust

Did you set up an outputs.conf on the forwarder to send to the indexer?
http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Outputsconf

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...