Getting Data In

splunk list forward-server

duncanuno
Explorer

Hi, Windows query

I have a non AD Windows server 2008R2 setup x 3 servers. Simple setup for 2 servers to send data to Splunk server on 3rd server.
"Splunk" server with latest version of Splunk installed using Splunk web userid "admin", receiver port setup for default 9997

Second server where I have run splunkforwarder5.02....msi and at no stage am I prompted for user id or password. Selected all options however no certificate info. When testing to see status of forwarder (after restarting both Splunk and forwarder server) I get asked for a userid: and password:. Is this the Splunk web userid? - have tried this and fails, also tried the local admin userid - fails.

Firewalls on both disabled - am getting prompted for userid however I am not sure where this challenge is being generated.

Any ideas please?

Thanks

Tags (1)
0 Karma
1 Solution

jbsplunk
Splunk Employee
Splunk Employee

Splunk is asking you to login as you're performing an action that requires you to be authenticated. The passwords on one instance are completely independent one another, and the default credentials will always be an l/p of admin/changeme.

View solution in original post

jbsplunk
Splunk Employee
Splunk Employee

Splunk is asking you to login as you're performing an action that requires you to be authenticated. The passwords on one instance are completely independent one another, and the default credentials will always be an l/p of admin/changeme.

duncanuno
Explorer

Excellent - when entering default credentials

C:\Program Files\SplunkUniversalForwarder\bin>splunk list forward-server

Splunk username: admin / Password:

Active forwards: None

Configured but inactive forwards: splunk.xxx.com:9997

Nothing further was done but some head scratching and coffee drinking, checked again and voila!

Active forwards: splunk.xxx.com:9997

Configured but inactive forwards: None

Now to see if this can be replicated smoothly on my third server!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...