Deployment Architecture

Splunk Cloud Forwarder on Linux

kleanthis
New Member

Hello,

I am following the guide here : https://docs.splunk.com/Documentation/SplunkCloud/7.0.0/User/ForwardDataToSplunkCloudFromLinux

At some point it sais i need to install splunkclouduf.spl file which i have downloaded from my cloud instance using : splunk install app <full path to splunkclouduf.spl> -auth <username>:<password> . Problem is whenever i try to run that command i get : Not Found . I am 100% sure the path and credentials are correct . What am i missing ? Or is this a step i need or shall i skip it ?

0 Karma

FrankVl
Ultra Champion

Are you sure you're in the right directory (bin folder inside your splunk universal forwarder installation folder)? Have your tried ./splunk... instead of just splunk...

0 Karma

kleanthis
New Member

Yes and Yes.

root@host:/home/devuser/splunkforwarder/bin# ./splunk install app ../../splunkclouduf.spl -auth admin:changeme
Not Found

0 Karma

FrankVl
Ultra Champion

Does the user you run splunk as (non-root I hope) have permissions to access the .spl file?

Do other splunk commands work (e.g. ./splunk status)?

0 Karma

kleanthis
New Member

root@host:/home/devuser/splunkforwarder/bin# ./splunk status
splunkd is not running.

I think i got it. I must have messed up something and splunk did not start . I will start from scratch and see what happens . Thanx.

0 Karma

FrankVl
Ultra Champion

Ok, so the basic thing works, it's specifically that install command that fails. Not sure if splunk needs to be running to perform ./splunk install...

0 Karma

kleanthis
New Member

Yes and Yes.

root@host:/home/devuser/splunkforwarder/bin# ./splunk install app ../../splunkclouduf.spl -auth admin:changeme
Not Found

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...