Deployment Architecture

Splunk Cloud Forwarder on Linux

kleanthis
New Member

Hello,

I am following the guide here : https://docs.splunk.com/Documentation/SplunkCloud/7.0.0/User/ForwardDataToSplunkCloudFromLinux

At some point it sais i need to install splunkclouduf.spl file which i have downloaded from my cloud instance using : splunk install app <full path to splunkclouduf.spl> -auth <username>:<password> . Problem is whenever i try to run that command i get : Not Found . I am 100% sure the path and credentials are correct . What am i missing ? Or is this a step i need or shall i skip it ?

0 Karma

FrankVl
Ultra Champion

Are you sure you're in the right directory (bin folder inside your splunk universal forwarder installation folder)? Have your tried ./splunk... instead of just splunk...

0 Karma

kleanthis
New Member

Yes and Yes.

root@host:/home/devuser/splunkforwarder/bin# ./splunk install app ../../splunkclouduf.spl -auth admin:changeme
Not Found

0 Karma

FrankVl
Ultra Champion

Does the user you run splunk as (non-root I hope) have permissions to access the .spl file?

Do other splunk commands work (e.g. ./splunk status)?

0 Karma

kleanthis
New Member

root@host:/home/devuser/splunkforwarder/bin# ./splunk status
splunkd is not running.

I think i got it. I must have messed up something and splunk did not start . I will start from scratch and see what happens . Thanx.

0 Karma

FrankVl
Ultra Champion

Ok, so the basic thing works, it's specifically that install command that fails. Not sure if splunk needs to be running to perform ./splunk install...

0 Karma

kleanthis
New Member

Yes and Yes.

root@host:/home/devuser/splunkforwarder/bin# ./splunk install app ../../splunkclouduf.spl -auth admin:changeme
Not Found

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...