Getting Data In

Splunk Forwarder: Why is there no listing of the Win10 VM in either hosts or source list?

Aus01
New Member

I have installed the splunk forwarder on a Windows 10 VM and have splunk installed on a Debian VM. I have restarted the splunk forwarder on the Win10 VM but when i log into splunk enterprise on the Debian VM and go into Search & Reporting > Data Summary there is no listing of the Win10 VM in either hosts or source list. 

Does anyone have any idea what i could be doing wrong or any suggestions of things i could try?

Labels (3)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Just because you installed two components, doesn't mean they know how to talk to each other.

1. What version of Splunk did you install? (Splunk Free or Splunk Enterprise with a proper commercial or trial license)

2. Did you configure the UF on/after installation in any way?

0 Karma

gcusello
SplunkTrust
SplunkTrust

HI @Aus01,

the usual issue in this situations are the following:

  • did you enabled Receiving on the Splunk Enterprise VM [ Settings > Forwardring and Receiving > Receiving ]?
  • did you configured your Universal Forwarder to send logs to the Splunk Enterprise VM?
  • Did you disabled local firewall on the both the machines?
  • Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...