Getting Data In

Why is the Splunk universal forwarder not pushing data to indexer?

jpbelauskas1
New Member

I recently upgraded a workstation to Win10 Enterprise. I installed the Splunk universal forwarder, however I am not collecting any data from the workstation at the indexer. I believe it has something to do with certificates, but I am not very well versed in the product. I'm afraid the documentation isn't helping much either.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

So the forwarder worked on a previous version of Windows but is not working after upgrading to Win10?

Can you check your outputs.conf under SPLUNK_HOME\etc\system\local and verify its pointing to the correct indexer(s)?

If it is, you should then go to SPLUNK_HOME\etc\var\log\splunk and open up splunkd.log and see if its complaining about anything

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...