Getting Data In

Cannot figure Universal forwarder out

chrisscott1
New Member

I have done 3-4 days of research and have been striking out. Here is the process that I follow. I install the universal forwarder on our web server to monitor system logs. Below are the steps:

  1. I execute the installable msi file from cmd prompt to create the service and start the installation process.

  2. I install the UF to C:\Program Files\SplunkUniversalForwarder\

  3. I leave the deployment server blank.

  4. Now for recieiving indexer the main splunk cleint is on z8 so I ping z8 get the IP address and put that in as the host name and assign it to port 9997 which is the default port.. is this correct?

  5. I leave the SSL certificate informaiton blank,

  6. I choose local data only.

  7. I select system log and browse to the directory path for thwere the websites IIS logs are pointing and install the service.

From here I do not know what to do. Any help would be appreciated. Am I doing this right?

Tags (3)
0 Karma

FunPolice
Path Finder

Have you told the Splunk server (z8) to listen for information from a forwarder? Go to Manager - Forwarding and Receiving to turn on receiving. Make sure to download the Deployment Monitor app to keep an eye on it as well.

You can look for relevant events in the _internal index to troubleshoot - try searching

index=_internal sourcetype="splunkd"

for starters.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...