Getting Data In

Cannot figure Universal forwarder out

New Member

I have done 3-4 days of research and have been striking out. Here is the process that I follow. I install the universal forwarder on our web server to monitor system logs. Below are the steps:

  1. I execute the installable msi file from cmd prompt to create the service and start the installation process.

  2. I install the UF to C:\Program Files\SplunkUniversalForwarder\

  3. I leave the deployment server blank.

  4. Now for recieiving indexer the main splunk cleint is on z8 so I ping z8 get the IP address and put that in as the host name and assign it to port 9997 which is the default port.. is this correct?

  5. I leave the SSL certificate informaiton blank,

  6. I choose local data only.

  7. I select system log and browse to the directory path for thwere the websites IIS logs are pointing and install the service.

From here I do not know what to do. Any help would be appreciated. Am I doing this right?

Tags (3)
0 Karma

Path Finder

Have you told the Splunk server (z8) to listen for information from a forwarder? Go to Manager - Forwarding and Receiving to turn on receiving. Make sure to download the Deployment Monitor app to keep an eye on it as well.

You can look for relevant events in the _internal index to troubleshoot - try searching

index=_internal sourcetype="splunkd"

for starters.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!