Deployment Architecture

About splunk installation

arif751
New Member

I am noob in SOC, currently started learning. I use Splunk for practice.. So recently, I installed Universal Forwarder in my VMWare Windows 10 OS and Splunk enterprise in my main desktop. During universal forwarder installation, I gave my main PC ip in the Deployment host & VM windows ip in Receiving host option (Port was default). 

But after installing, my forwarder management is not showing any client in there in Splunk. I tried my main ip in both., changed my IP to static to dynamic, chose Bridged & NAT both network option in VM. Nothing is working.

Splunk is not connecting to client. Need urgent help to start practicing!! Hoping the actual solution.

Thanks in advance.

Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Since you do not have a Deployment Server (they're optional), leave the "Deployment host" box empty when installing the UF.  Put your Splunk Enterprise IP address in the "Receiving host" box.  In Splunk Enterprise, enable data reception by going to Settings->Forwarding and Receiving and clicking on "Configure receiving".

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...