Deployment Architecture

Splunk Cloud Forwarder on Linux

kleanthis
New Member

Hello,

I am following the guide here : https://docs.splunk.com/Documentation/SplunkCloud/7.0.0/User/ForwardDataToSplunkCloudFromLinux

At some point it sais i need to install splunkclouduf.spl file which i have downloaded from my cloud instance using : splunk install app <full path to splunkclouduf.spl> -auth <username>:<password> . Problem is whenever i try to run that command i get : Not Found . I am 100% sure the path and credentials are correct . What am i missing ? Or is this a step i need or shall i skip it ?

0 Karma

FrankVl
Ultra Champion

Are you sure you're in the right directory (bin folder inside your splunk universal forwarder installation folder)? Have your tried ./splunk... instead of just splunk...

0 Karma

kleanthis
New Member

Yes and Yes.

root@host:/home/devuser/splunkforwarder/bin# ./splunk install app ../../splunkclouduf.spl -auth admin:changeme
Not Found

0 Karma

FrankVl
Ultra Champion

Does the user you run splunk as (non-root I hope) have permissions to access the .spl file?

Do other splunk commands work (e.g. ./splunk status)?

0 Karma

kleanthis
New Member

root@host:/home/devuser/splunkforwarder/bin# ./splunk status
splunkd is not running.

I think i got it. I must have messed up something and splunk did not start . I will start from scratch and see what happens . Thanx.

0 Karma

FrankVl
Ultra Champion

Ok, so the basic thing works, it's specifically that install command that fails. Not sure if splunk needs to be running to perform ./splunk install...

0 Karma

kleanthis
New Member

Yes and Yes.

root@host:/home/devuser/splunkforwarder/bin# ./splunk install app ../../splunkclouduf.spl -auth admin:changeme
Not Found

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...