I have set up a universal forwarder to read logs from kiwi syslog server.
Universal Forwarder is set to forward logs to the Indexer via Heavy Forwarder.
I have also set up the Heavy Forwarder as deployment server.
I have deployed the following inputs.conf to the U.F by deploying an app from the deployment server.
[monitor://C:\Program Files (x86)\Syslogd\Logs\x.x.x.x\log*.txt]
index = main
sourcetype = syslog
disabled = false
With all the above settings, I still cant see any logs on the Indexer.
I have confirmed following things already,
splunk btool inputs list monitor command also does not work on the U.F
Please help me troubleshoot this.
Thank you.
There are only INFO messages.
Strangely, after I restarted the universal forwarder and re-deployed the app, I was able to see logs on the Indexer now. However, I am still unsure where was the fault.
Does restarting the U.F or splunk reload deploy-server
both required to apply config settings on U.F ?
Also, in Forwarder Management, it shows me all info like apps, server classes and deployment client, however, in Settings-->Server Settings--> Deployment Client, it shows nothing at all. Any reason why ?
There are only INFO messages.
Strangely, after I restarted the universal forwarder and re-deployed the app, I was able to see logs on the Indexer now. However, I am still unsure where was the fault.
Does restarting the U.F or splunk reload deploy-server
both required to apply config settings on U.F ?
Also, in Forwarder Management, it shows me all info like apps, server classes and deployment client, however, in Settings-->Server Settings--> Deployment Client, it shows nothing at all. Any reason why ?
Any messages in the splunkd.log file on the universal forwarder? It would be in Splunk_home\var\log\splunk\splunkd.log