Deployment Architecture

About splunk installation

arif751
New Member

I am noob in SOC, currently started learning. I use Splunk for practice.. So recently, I installed Universal Forwarder in my VMWare Windows 10 OS and Splunk enterprise in my main desktop. During universal forwarder installation, I gave my main PC ip in the Deployment host & VM windows ip in Receiving host option (Port was default). 

But after installing, my forwarder management is not showing any client in there in Splunk. I tried my main ip in both., changed my IP to static to dynamic, chose Bridged & NAT both network option in VM. Nothing is working.

Splunk is not connecting to client. Need urgent help to start practicing!! Hoping the actual solution.

Thanks in advance.

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since you do not have a Deployment Server (they're optional), leave the "Deployment host" box empty when installing the UF.  Put your Splunk Enterprise IP address in the "Receiving host" box.  In Splunk Enterprise, enable data reception by going to Settings->Forwarding and Receiving and clicking on "Configure receiving".

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...