Getting Data In

Why am I unable to connect to Splunk cloud from universal forwarder?

yantriks
Engager

I have installed the universal forwarder according to

http://docs.splunk.com/Documentation/SplunkCloud/7.0.5/User/ForwardDataToSplunkCloudFromLinux

But in Step 5, I am not able find my host on Splunk cloud.

I also tried adding the forward server using "splunk add forward-server prd-p-npv9nbngb7j9.cloud.splunk.com:9997" and manually added monitor to inputs.conf.

telnet prd-p-npv9nbngb7j9.cloud.splunk.com 9997 -->gave a timeout

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

You need to log into your cloud instance and download the credentials app, I believe it is under the Universal Forwarder app on the left hand side. This app will point to your cloud instance and also contains the certificates for secure sending of your data.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...