Deployment Architecture

Splunk forwarder, instance, Sending log from my Linux installed on Hyper-v

ibztek
Loves-to-Learn Lots

I'm trying to send log from my Linux installed on Hyper-v windows into my Splunk instance and it data doesn't seem to reach it's destination. I have entered the port number in my Splunk instance - Receive data - configure receiving and entered my port number. i edited my input.conf file and why can't I see my log in Splunk???

Labels (1)
0 Karma

ibztek
Loves-to-Learn Lots

write now i am getting error when i try to ping splunkdeploy.customerscallnow.com: name or service not known..i seem to follow a prety nice instruction but i am not yet able to connect 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This error told that your DNS service cannot found it for that name. You should fix it first and then check if UF works after that.
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check the contents of /opt/splunkforwarder/var/log/splunk/splunkd.log on your forwarder (especially the last entries in that log). That should show you whether it tried to connect to the indexer and if it did, why it failed.

0 Karma

ibztek
Loves-to-Learn Lots

it is tryiing to connect but it failes with name or service uknown

0 Karma

PickleRick
SplunkTrust
SplunkTrust

So either your outputs.conf in the forwarder point to a wrong server or you have DNS problems in your VM.

0 Karma

ibztek
Loves-to-Learn Lots
index=_internal host=<your UF node name + *> earliest=1

doesn't seem to reply anything.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could find your UF’s name from its $SPLUNK_HOME/var/log/splunk/splunkd.log. That log file contains also information if it can send it’s own logs to splunk server.

I assume that you have outputs.conf on place and it has defined your splunk server as a target?

0 Karma

ibztek
Loves-to-Learn Lots

iam trying to find my uf node name..im very new to splunk

0 Karma

ibztek
Loves-to-Learn Lots

i don't see my host in the splunk at all.

0 Karma

ibztek
Loves-to-Learn Lots

how can i do that, can you be a bit specific ? thank you

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could make a query on sh like 

index=_internal host=<your UF node name + *> earliest=1

this should show some entries, if your UF has connection to server. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you see that your UF has sent its internal logs to server?

r. Ismo

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...