Getting Data In

Splunk Forwarder: Why is there no listing of the Win10 VM in either hosts or source list?

Aus01
New Member

I have installed the splunk forwarder on a Windows 10 VM and have splunk installed on a Debian VM. I have restarted the splunk forwarder on the Win10 VM but when i log into splunk enterprise on the Debian VM and go into Search & Reporting > Data Summary there is no listing of the Win10 VM in either hosts or source list. 

Does anyone have any idea what i could be doing wrong or any suggestions of things i could try?

Labels (3)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Just because you installed two components, doesn't mean they know how to talk to each other.

1. What version of Splunk did you install? (Splunk Free or Splunk Enterprise with a proper commercial or trial license)

2. Did you configure the UF on/after installation in any way?

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Aus01,

the usual issue in this situations are the following:

  • did you enabled Receiving on the Splunk Enterprise VM [ Settings > Forwardring and Receiving > Receiving ]?
  • did you configured your Universal Forwarder to send logs to the Splunk Enterprise VM?
  • Did you disabled local firewall on the both the machines?
  • Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...