I have installed a universal-forwarder on a Ubuntu Linux box without error, here is some validation:
Splunk list forward-server
The forward does show up in monitor, but when I get to add the Forwarder under Settings -> Data. It doesn't show any forwarders available and show the refresh button. I did also download and copy Splunk for Linux under /opt/splunkforwarder/etc/apps/SplunkTAlinux as first goal is to get performance data into the cloud.
Did you enable to configuration ? Read through the "Enable the data and scripted inputs with configuration files" section in the below link.
Note on the install, you also need it on the Search Head and Indexers. You may need to raise a Splunk Support ticket for this
Thank You for your reply!
There is no $SPLUNKHOME/etc/apps/SplunkTAnix/local directory there is a $SPLUNKHOME/etc/apps/SplunkTAlinux /default directory. There also is no existing input.conf file, the files available in $SPLUNKHOME/etc/apps/SplunkTA_linux /default are:
/opt/splunkforwarder/etc/apps/SplunkTAlinux/default$ ls -ltr
-rw-r--r-- 1 splunk splunk 2833 Apr 19 2018 transforms.conf
-rw-r--r-- 1 splunk splunk 1481 Apr 19 2018 tags.conf
-rw-r--r-- 1 splunk splunk 7821 Apr 19 2018 props.conf
-rw-r--r-- 1 splunk splunk 2802 Apr 19 2018 eventtypes.conf
-rw-r--r-- 1 splunk splunk 24647 Apr 19 2018 eventgen.conf
drwxr-xr-x 3 splunk splunk 16 Apr 19 2018 data
-rw-r--r-- 1 splunk splunk 457 Apr 19 2018 app.conf
This is SplunkTAlinux which in my understanding is different then Splunk Add-on for Unix and Linux, I used SplunkTAlinux because it didn't require logging a support ticket.