Getting Data In

Splunk Forwarder: Why is there no listing of the Win10 VM in either hosts or source list?

Aus01
New Member

I have installed the splunk forwarder on a Windows 10 VM and have splunk installed on a Debian VM. I have restarted the splunk forwarder on the Win10 VM but when i log into splunk enterprise on the Debian VM and go into Search & Reporting > Data Summary there is no listing of the Win10 VM in either hosts or source list. 

Does anyone have any idea what i could be doing wrong or any suggestions of things i could try?

Labels (3)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Just because you installed two components, doesn't mean they know how to talk to each other.

1. What version of Splunk did you install? (Splunk Free or Splunk Enterprise with a proper commercial or trial license)

2. Did you configure the UF on/after installation in any way?

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Aus01,

the usual issue in this situations are the following:

  • did you enabled Receiving on the Splunk Enterprise VM [ Settings > Forwardring and Receiving > Receiving ]?
  • did you configured your Universal Forwarder to send logs to the Splunk Enterprise VM?
  • Did you disabled local firewall on the both the machines?
  • Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...