Getting Data In

Splunk Forwarder: Why is there no listing of the Win10 VM in either hosts or source list?

Aus01
New Member

I have installed the splunk forwarder on a Windows 10 VM and have splunk installed on a Debian VM. I have restarted the splunk forwarder on the Win10 VM but when i log into splunk enterprise on the Debian VM and go into Search & Reporting > Data Summary there is no listing of the Win10 VM in either hosts or source list. 

Does anyone have any idea what i could be doing wrong or any suggestions of things i could try?

Labels (3)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Just because you installed two components, doesn't mean they know how to talk to each other.

1. What version of Splunk did you install? (Splunk Free or Splunk Enterprise with a proper commercial or trial license)

2. Did you configure the UF on/after installation in any way?

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Aus01,

the usual issue in this situations are the following:

  • did you enabled Receiving on the Splunk Enterprise VM [ Settings > Forwardring and Receiving > Receiving ]?
  • did you configured your Universal Forwarder to send logs to the Splunk Enterprise VM?
  • Did you disabled local firewall on the both the machines?
  • Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...