Deployment Architecture

Splunk forwarder, instance, Sending log from my Linux installed on Hyper-v

ibztek
Loves-to-Learn Lots

I'm trying to send log from my Linux installed on Hyper-v windows into my Splunk instance and it data doesn't seem to reach it's destination. I have entered the port number in my Splunk instance - Receive data - configure receiving and entered my port number. i edited my input.conf file and why can't I see my log in Splunk???

Labels (1)
0 Karma

ibztek
Loves-to-Learn Lots

write now i am getting error when i try to ping splunkdeploy.customerscallnow.com: name or service not known..i seem to follow a prety nice instruction but i am not yet able to connect 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This error told that your DNS service cannot found it for that name. You should fix it first and then check if UF works after that.
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check the contents of /opt/splunkforwarder/var/log/splunk/splunkd.log on your forwarder (especially the last entries in that log). That should show you whether it tried to connect to the indexer and if it did, why it failed.

0 Karma

ibztek
Loves-to-Learn Lots

it is tryiing to connect but it failes with name or service uknown

0 Karma

PickleRick
SplunkTrust
SplunkTrust

So either your outputs.conf in the forwarder point to a wrong server or you have DNS problems in your VM.

0 Karma

ibztek
Loves-to-Learn Lots
index=_internal host=<your UF node name + *> earliest=1

doesn't seem to reply anything.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could find your UF’s name from its $SPLUNK_HOME/var/log/splunk/splunkd.log. That log file contains also information if it can send it’s own logs to splunk server.

I assume that you have outputs.conf on place and it has defined your splunk server as a target?

0 Karma

ibztek
Loves-to-Learn Lots

iam trying to find my uf node name..im very new to splunk

0 Karma

ibztek
Loves-to-Learn Lots

i don't see my host in the splunk at all.

0 Karma

ibztek
Loves-to-Learn Lots

how can i do that, can you be a bit specific ? thank you

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could make a query on sh like 

index=_internal host=<your UF node name + *> earliest=1

this should show some entries, if your UF has connection to server. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you see that your UF has sent its internal logs to server?

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...