Archive

not getting universal forwarder to load up correctly

New Member

I'm completely confused.
After reading thru the many Q/A on universal forwarder and installing on WAS, didn't help
I want the Universal forwarder on a WAS box to send to Indexer on UNIX box. I loaded UF followed by Splunk Forwarder Add-on for WAS all on the WAS box.

1) Do I have to have a full Splunk instance initially?

2) if not, from what directory do I install (unpack the tar file) for the Add-on portion? somehow I have 3 directories a) splunk, b)splunkforwarderaddon_was, c)splunkforwarder. this is confusing the heck out of me.

3) Seems that the forwarder defaults to port 8089 and not 8000. I think I can work around that based on what I've read. Just need to get past everything else.

PLEASE HELP

Tags (2)
0 Karma

New Member

Thanks for the response.
yes, ran the jar file to create the outputs.conf file and was able to get data sent to indexer instance. my question is more directed to if needing a full Splunk instance on the WAS server before I loaded the Universal Forwarder. I think I have my answer since I tried both with/without.
I got confused on the directories that the Forwarder and the Forwarder Add-on created. I loaded the forwarder Add-on & the Appliance add-on under 'apps' directory '/splunkforwarder/etc/apps' which I'm assuming was the correct way to go.

0 Karma

New Member

Thanks for the response.
yes, ran the jar file to create the outputs.conf file and was able to get data sent to indexer instance. my question is more directed to if needing a full Splunk instance on the WAS server before I loaded the Universal Forwarder. I think I have my answer since I tried both with/without.
I got confused on the directories that the Forwarder and the Forwarder Add-on created. I loaded the forwarder Add-on & the Appliance add-on under 'apps' directory '/splunkforwarder/etc/apps' which I'm assuming was the correct way to go.

0 Karma

SplunkTrust
SplunkTrust

Did you set up an outputs.conf on the forwarder to send to the indexer?
http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Outputsconf

0 Karma