Getting Data In

Linux Forwarder Shows up Monitor, but Can't add data to Splunk Cloud?

cjwallac35
New Member

I have installed a universal-forwarder on a Ubuntu Linux box without error, here is some validation:

Splunk list forward-server
Active forwards:
input-prd-p-xxxxxxxxxx.cloud.splunk.com:9997 (ssl)

The forward does show up in monitor, but when I get to add the Forwarder under Settings -> Data. It doesn't show any forwarders available and show the refresh button. I did also download and copy Splunk for Linux under /opt/splunkforwarder/etc/apps/Splunk_TA_linux as first goal is to get performance data into the cloud.

Thank You!

Tags (2)
0 Karma

anmolpatel
Builder

Did you enable to configuration ? Read through the "Enable the data and scripted inputs with configuration files" section in the below link.

https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Enabledataandscriptedinputs

Note on the install, you also need it on the Search Head and Indexers. You may need to raise a Splunk Support ticket for this
https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Install

0 Karma

cjwallac35
New Member

Thank You for your reply!

There is no $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local directory there is a $SPLUNK_HOME/etc/apps/Splunk_TA_linux /default directory. There also is no existing input.conf file, the files available in $SPLUNK_HOME/etc/apps/Splunk_TA_linux /default are:

/opt/splunkforwarder/etc/apps/Splunk_TA_linux/default$ ls -ltr
total 52
-rw-r--r-- 1 splunk splunk 2833 Apr 19 2018 transforms.conf
-rw-r--r-- 1 splunk splunk 1481 Apr 19 2018 tags.conf
-rw-r--r-- 1 splunk splunk 7821 Apr 19 2018 props.conf
-rw-r--r-- 1 splunk splunk 2802 Apr 19 2018 eventtypes.conf
-rw-r--r-- 1 splunk splunk 24647 Apr 19 2018 eventgen.conf
drwxr-xr-x 3 splunk splunk 16 Apr 19 2018 data
-rw-r--r-- 1 splunk splunk 457 Apr 19 2018 app.conf

This is Splunk_TA_linux which in my understanding is different then Splunk Add-on for Unix and Linux, I used Splunk_TA_linux because it didn't require logging a support ticket.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...