Getting Data In

Why am I unable to forward logs from a FreeBSD machine to our managed Splunk Cloud instance?

Michael_Carlisl
Explorer

Hi All,

I'm trying to forward logs from a FreeBSD machine to our Splunk Cloud instance. I've downloaded the spl file that is located within the site, but when I try to install the app, it is still not connecting. I validated that the port is open, and I have not done anything with the conf files other than using the CLI commands to add monitoring. One thing I did notice is that our Windows machines have (ssl) beside their "Active forwards" where as my "Inactive forwards" do not have (ssl) beside them. I had assumed the certificate was part of the .spl install. Any ideas?

Best,
Michael

0 Karma
1 Solution

Michael_Carlisl
Explorer

So it turns out the spl file retrieved from the Splunk Cloud instance set Outputs.conf file in the splunkuniversalforwarder folder to a site it could not resolve. I updated that site to the ip equivalent and it started working. Not sure why this works in our non-unix environments.

View solution in original post

0 Karma

Michael_Carlisl
Explorer

So it turns out the spl file retrieved from the Splunk Cloud instance set Outputs.conf file in the splunkuniversalforwarder folder to a site it could not resolve. I updated that site to the ip equivalent and it started working. Not sure why this works in our non-unix environments.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...