Getting Data In

How do I configure a Windows universal forwarder to send data to a receiver?


I have 2 universal forwarders pointing to 1 receiver. All are Windows 64.

I confirm that they are both "seen" by using the dashboard "Forwarders: Deployment" in Splunk Web on the receiver.

I don't know how to get the data into Splunk so it can be indexed. If I choose "data inputs" and choose one of the "forwarder" options, it just says "There are currently no forwarders configured as deployment clients to this instance".

0 Karma


I suggest you to go through this link once:
Setup Universal Forwarder

As suggested in the above link, please make sure that firewall is not blocking that port.

0 Karma

Path Finder

Did you check the Splunk Log-Files (on both, receiver and forwarder)? Is your configuration complete (inputs.conf @ receiver, outputs.conf @ forwarders)?

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...