Deployment Architecture

not getting universal forwarder to load up correctly

jchilovich
New Member

I'm completely confused.
After reading thru the many Q/A on universal forwarder and installing on WAS, didn't help
I want the Universal forwarder on a WAS box to send to Indexer on UNIX box. I loaded UF followed by Splunk Forwarder Add-on for WAS all on the WAS box.

1) Do I have to have a full Splunk instance initially?

2) if not, from what directory do I install (unpack the tar file) for the Add-on portion? somehow I have 3 directories a) splunk, b)splunk_forwarder_addon_was, c)splunkforwarder. this is confusing the heck out of me.

3) Seems that the forwarder defaults to port 8089 and not 8000. I think I can work around that based on what I've read. Just need to get past everything else.

PLEASE HELP

Tags (2)
0 Karma

jchilovich
New Member

Thanks for the response.
yes, ran the jar file to create the outputs.conf file and was able to get data sent to indexer instance. my question is more directed to if needing a full Splunk instance on the WAS server before I loaded the Universal Forwarder. I think I have my answer since I tried both with/without.
I got confused on the directories that the Forwarder and the Forwarder Add-on created. I loaded the forwarder Add-on & the Appliance add-on under 'apps' directory '/splunkforwarder/etc/apps' which I'm assuming was the correct way to go.

0 Karma

jchilovich
New Member

Thanks for the response.
yes, ran the jar file to create the outputs.conf file and was able to get data sent to indexer instance. my question is more directed to if needing a full Splunk instance on the WAS server before I loaded the Universal Forwarder. I think I have my answer since I tried both with/without.
I got confused on the directories that the Forwarder and the Forwarder Add-on created. I loaded the forwarder Add-on & the Appliance add-on under 'apps' directory '/splunkforwarder/etc/apps' which I'm assuming was the correct way to go.

0 Karma

starcher
Influencer

Did you set up an outputs.conf on the forwarder to send to the indexer?
http://docs.splunk.com/Documentation/Splunk/5.0.3/Admin/Outputsconf

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...