I am noob in SOC, currently started learning. I use Splunk for practice.. So recently, I installed Universal Forwarder in my VMWare Windows 10 OS and Splunk enterprise in my main desktop. During universal forwarder installation, I gave my main PC ip in the Deployment host & VM windows ip in Receiving host option (Port was default).
But after installing, my forwarder management is not showing any client in there in Splunk. I tried my main ip in both., changed my IP to static to dynamic, chose Bridged & NAT both network option in VM. Nothing is working.
Splunk is not connecting to client. Need urgent help to start practicing!! Hoping the actual solution.
Thanks in advance.
Since you do not have a Deployment Server (they're optional), leave the "Deployment host" box empty when installing the UF. Put your Splunk Enterprise IP address in the "Receiving host" box. In Splunk Enterprise, enable data reception by going to Settings->Forwarding and Receiving and clicking on "Configure receiving".