Deployment Architecture

Splunk forwarder, instance, Sending log from my Linux installed on Hyper-v

ibztek
Loves-to-Learn Lots

I'm trying to send log from my Linux installed on Hyper-v windows into my Splunk instance and it data doesn't seem to reach it's destination. I have entered the port number in my Splunk instance - Receive data - configure receiving and entered my port number. i edited my input.conf file and why can't I see my log in Splunk???

Labels (1)
0 Karma

ibztek
Loves-to-Learn Lots

write now i am getting error when i try to ping splunkdeploy.customerscallnow.com: name or service not known..i seem to follow a prety nice instruction but i am not yet able to connect 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This error told that your DNS service cannot found it for that name. You should fix it first and then check if UF works after that.
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check the contents of /opt/splunkforwarder/var/log/splunk/splunkd.log on your forwarder (especially the last entries in that log). That should show you whether it tried to connect to the indexer and if it did, why it failed.

0 Karma

ibztek
Loves-to-Learn Lots

it is tryiing to connect but it failes with name or service uknown

0 Karma

PickleRick
SplunkTrust
SplunkTrust

So either your outputs.conf in the forwarder point to a wrong server or you have DNS problems in your VM.

0 Karma

ibztek
Loves-to-Learn Lots
index=_internal host=<your UF node name + *> earliest=1

doesn't seem to reply anything.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could find your UF’s name from its $SPLUNK_HOME/var/log/splunk/splunkd.log. That log file contains also information if it can send it’s own logs to splunk server.

I assume that you have outputs.conf on place and it has defined your splunk server as a target?

0 Karma

ibztek
Loves-to-Learn Lots

iam trying to find my uf node name..im very new to splunk

0 Karma

ibztek
Loves-to-Learn Lots

i don't see my host in the splunk at all.

0 Karma

ibztek
Loves-to-Learn Lots

how can i do that, can you be a bit specific ? thank you

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could make a query on sh like 

index=_internal host=<your UF node name + *> earliest=1

this should show some entries, if your UF has connection to server. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you see that your UF has sent its internal logs to server?

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...