Getting Data In

How to configure Universal Forwarder on my personal machine where Splunk Enterprise is installed for learning purpose?

ashishmaind2499
New Member

I installed Splunk Universal Fwd and Splunk Enterprise on my C drive. I created a sample file and modified the inputs.conf as mentioned in one of the ans(link given below) and enabled the receiver by setting port to 9997. Do we have to modify/create outputs.conf file? I tried creating outputs.conf too..but no use. In outputs.conf I gave the server name as localhost and port as 9997. Am I missing something? Also, do we have to modify anything in distributed search? I assume my Splunk Enterprise is acting both as SH and Indexer.
Have referred to below ans but didnt got the answer
https://answers.splunk.com/answers/490343/how-to-properly-configure-universal-forwarder-loca.html#an...

0 Karma

jkat54
SplunkTrust
SplunkTrust

Please share your inputs.conf and outputs.conf.

Also check if firewall is blocking any ports please.

0 Karma

xpac
SplunkTrust
SplunkTrust

If you're running both on the same system, you might run into trouble because, by default, both want to listen on TCP 9997.
Check if both instances actually run, you might have to change the splunkd port of the UF using server.conf.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...