Getting Data In

Linux Forwarder Shows up Monitor, but Can't add data to Splunk Cloud?

cjwallac35
New Member

I have installed a universal-forwarder on a Ubuntu Linux box without error, here is some validation:

Splunk list forward-server
Active forwards:
input-prd-p-xxxxxxxxxx.cloud.splunk.com:9997 (ssl)

The forward does show up in monitor, but when I get to add the Forwarder under Settings -> Data. It doesn't show any forwarders available and show the refresh button. I did also download and copy Splunk for Linux under /opt/splunkforwarder/etc/apps/Splunk_TA_linux as first goal is to get performance data into the cloud.

Thank You!

Tags (2)
0 Karma

anmolpatel
Builder

Did you enable to configuration ? Read through the "Enable the data and scripted inputs with configuration files" section in the below link.

https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Enabledataandscriptedinputs

Note on the install, you also need it on the Search Head and Indexers. You may need to raise a Splunk Support ticket for this
https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Install

0 Karma

cjwallac35
New Member

Thank You for your reply!

There is no $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local directory there is a $SPLUNK_HOME/etc/apps/Splunk_TA_linux /default directory. There also is no existing input.conf file, the files available in $SPLUNK_HOME/etc/apps/Splunk_TA_linux /default are:

/opt/splunkforwarder/etc/apps/Splunk_TA_linux/default$ ls -ltr
total 52
-rw-r--r-- 1 splunk splunk 2833 Apr 19 2018 transforms.conf
-rw-r--r-- 1 splunk splunk 1481 Apr 19 2018 tags.conf
-rw-r--r-- 1 splunk splunk 7821 Apr 19 2018 props.conf
-rw-r--r-- 1 splunk splunk 2802 Apr 19 2018 eventtypes.conf
-rw-r--r-- 1 splunk splunk 24647 Apr 19 2018 eventgen.conf
drwxr-xr-x 3 splunk splunk 16 Apr 19 2018 data
-rw-r--r-- 1 splunk splunk 457 Apr 19 2018 app.conf

This is Splunk_TA_linux which in my understanding is different then Splunk Add-on for Unix and Linux, I used Splunk_TA_linux because it didn't require logging a support ticket.

0 Karma
Get Updates on the Splunk Community!

New Case Study Shows the Value of Partnering with Splunk Academic Alliance

The University of Nevada, Las Vegas (UNLV) is another premier research institution helping to shape the next ...

How to Monitor Google Kubernetes Engine (GKE)

We’ve looked at how to integrate Kubernetes environments with Splunk Observability Cloud, but what about ...

Index This | How can you make 45 using only 4?

October 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...