Deployment Architecture

not getting universal forwarder to load up correctly

jchilovich
New Member

I'm completely confused.
After reading thru the many Q/A on universal forwarder and installing on WAS, didn't help
I want the Universal forwarder on a WAS box to send to Indexer on UNIX box. I loaded UF followed by Splunk Forwarder Add-on for WAS all on the WAS box.

1) Do I have to have a full Splunk instance initially?

2) if not, from what directory do I install (unpack the tar file) for the Add-on portion? somehow I have 3 directories a) splunk, b)splunk_forwarder_addon_was, c)splunkforwarder. this is confusing the heck out of me.

3) Seems that the forwarder defaults to port 8089 and not 8000. I think I can work around that based on what I've read. Just need to get past everything else.

PLEASE HELP

Tags (2)
0 Karma

jchilovich
New Member

Thanks for the response.
yes, ran the jar file to create the outputs.conf file and was able to get data sent to indexer instance. my question is more directed to if needing a full Splunk instance on the WAS server before I loaded the Universal Forwarder. I think I have my answer since I tried both with/without.
I got confused on the directories that the Forwarder and the Forwarder Add-on created. I loaded the forwarder Add-on & the Appliance add-on under 'apps' directory '/splunkforwarder/etc/apps' which I'm assuming was the correct way to go.

0 Karma

jchilovich
New Member

Thanks for the response.
yes, ran the jar file to create the outputs.conf file and was able to get data sent to indexer instance. my question is more directed to if needing a full Splunk instance on the WAS server before I loaded the Universal Forwarder. I think I have my answer since I tried both with/without.
I got confused on the directories that the Forwarder and the Forwarder Add-on created. I loaded the forwarder Add-on & the Appliance add-on under 'apps' directory '/splunkforwarder/etc/apps' which I'm assuming was the correct way to go.

0 Karma

starcher
Influencer

Did you set up an outputs.conf on the forwarder to send to the indexer?
http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Outputsconf

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...