Getting Data In

Why am I unable to connect to Splunk cloud from universal forwarder?

yantriks
Engager

I have installed the universal forwarder according to

http://docs.splunk.com/Documentation/SplunkCloud/7.0.5/User/ForwardDataToSplunkCloudFromLinux

But in Step 5, I am not able find my host on Splunk cloud.

I also tried adding the forward server using "splunk add forward-server prd-p-npv9nbngb7j9.cloud.splunk.com:9997" and manually added monitor to inputs.conf.

telnet prd-p-npv9nbngb7j9.cloud.splunk.com 9997 -->gave a timeout

0 Karma

kmorris_splunk
Splunk Employee
Splunk Employee

You need to log into your cloud instance and download the credentials app, I believe it is under the Universal Forwarder app on the left hand side. This app will point to your cloud instance and also contains the certificates for secure sending of your data.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...