Getting Data In

Why am I unable to connect to Splunk cloud from universal forwarder?

yantriks
Engager

I have installed the universal forwarder according to

http://docs.splunk.com/Documentation/SplunkCloud/7.0.5/User/ForwardDataToSplunkCloudFromLinux

But in Step 5, I am not able find my host on Splunk cloud.

I also tried adding the forward server using "splunk add forward-server prd-p-npv9nbngb7j9.cloud.splunk.com:9997" and manually added monitor to inputs.conf.

telnet prd-p-npv9nbngb7j9.cloud.splunk.com 9997 -->gave a timeout

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

You need to log into your cloud instance and download the credentials app, I believe it is under the Universal Forwarder app on the left hand side. This app will point to your cloud instance and also contains the certificates for secure sending of your data.

0 Karma
Get Updates on the Splunk Community!

Build Scalable Security While Moving to Cloud - Guide From Clayton Homes

 Clayton Homes faced the increased challenge of strengthening their security posture as they went through ...

Mission Control | Explore the latest release of Splunk Mission Control (2.3)

We’re happy to announce the release of Mission Control 2.3 which includes several new and exciting features ...

Cloud Platform | Migrating your Splunk Cloud deployment to Python 3.7

Python 2.7, the last release of Python 2, reached End of Life back on January 1, 2020. As part of our larger ...