Deployment Architecture

How to forward data to unsplunk system?

niveditahanuman
New Member

I have configured three files outputs.conf, transforms.conf and props.conf but still I am not getting forwarded data on my unsplunk system.
Do I need to do more settings for this please let me know.

Tags (1)
0 Karma

lloydknight
Builder

Hello niveditahanumant,

Have you tried creating an inputs.conf with it?

https://docs.splunk.com/Documentation/Splunk/6.6.2/Admin/Inputsconf

But if you have an existing inputs.conf already including the data that you're monitoring, ensure that the needed port for forwarding (default port for forwarding data is 9997) is allowed in the firewall, and do basic connectivity tests like ping and telnet for assurance.

Hope it helps.

0 Karma

lloydknight
Builder

hello, what do you mean by unsplunk? Is it system/server without splunk installed on it?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...