Getting Data In

UF not in CMC

msatish
Explorer


Newly installed Universal forwarders on windows servers are forwarding logs to Splunk Cloud but newly installed forwarders name is not coming up in forwarders list in Cloud Monitoring Console. What could be the reason?

Labels (1)
0 Karma

livehybrid
Super Champion

Hi @msatish 

It looks like you need to "Rebuild Forwarder Assets". This can be done by going to Cloud Monitoring Console > Forwarders > Forwarder Monitoring Setup. and clicking on the "Rebuild Forwarder Assets" button.

I'd also recommend checking out the Review the Forwarder Monitoring Setup page docs which has more info about this and how to view/manage your forwarders via the CMC.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

kiran_panchavat
Influencer

@msatish 

You need to rebuild the forwarder asset table in the CMC for it to update properly.

Go to CMC > Forwarders > Forwarder Monitoring Setup > Rebuild Forwarder Assets

kiran_panchavat_0-1746684249585.png

Refer the below docs: 

Use the Forwarder dashboards - Splunk Documentation

Solved: monitoring console triggered alerts - missing forw... - Splunk Community

Solved: Why is our universal forwarder not visible in the ... - Splunk Community

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...