Getting Data In

Linux Forwarder Shows up Monitor, but Can't add data to Splunk Cloud?

cjwallac35
New Member

I have installed a universal-forwarder on a Ubuntu Linux box without error, here is some validation:

Splunk list forward-server
Active forwards:
input-prd-p-xxxxxxxxxx.cloud.splunk.com:9997 (ssl)

The forward does show up in monitor, but when I get to add the Forwarder under Settings -> Data. It doesn't show any forwarders available and show the refresh button. I did also download and copy Splunk for Linux under /opt/splunkforwarder/etc/apps/Splunk_TA_linux as first goal is to get performance data into the cloud.

Thank You!

Tags (2)
0 Karma

anmolpatel
Builder

Did you enable to configuration ? Read through the "Enable the data and scripted inputs with configuration files" section in the below link.

https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Enabledataandscriptedinputs

Note on the install, you also need it on the Search Head and Indexers. You may need to raise a Splunk Support ticket for this
https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Install

0 Karma

cjwallac35
New Member

Thank You for your reply!

There is no $SPLUNK_HOME/etc/apps/Splunk_TA_nix/local directory there is a $SPLUNK_HOME/etc/apps/Splunk_TA_linux /default directory. There also is no existing input.conf file, the files available in $SPLUNK_HOME/etc/apps/Splunk_TA_linux /default are:

/opt/splunkforwarder/etc/apps/Splunk_TA_linux/default$ ls -ltr
total 52
-rw-r--r-- 1 splunk splunk 2833 Apr 19 2018 transforms.conf
-rw-r--r-- 1 splunk splunk 1481 Apr 19 2018 tags.conf
-rw-r--r-- 1 splunk splunk 7821 Apr 19 2018 props.conf
-rw-r--r-- 1 splunk splunk 2802 Apr 19 2018 eventtypes.conf
-rw-r--r-- 1 splunk splunk 24647 Apr 19 2018 eventgen.conf
drwxr-xr-x 3 splunk splunk 16 Apr 19 2018 data
-rw-r--r-- 1 splunk splunk 457 Apr 19 2018 app.conf

This is Splunk_TA_linux which in my understanding is different then Splunk Add-on for Unix and Linux, I used Splunk_TA_linux because it didn't require logging a support ticket.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...