I have a syslog server running on my LAN and multiple devices logging to it. I tried installing the UF onto this host (Win 10 VM), but I'm not seeing any data appear in my Splunk Cloud Instance, nor am I getting any output from this command on the Win10 syslog host?
Any guidance would be apprecaited
C:\Program Files\SplunkUniversalForwarder\bin>splunk list monitor
C:\Program Files\SplunkUniversalForwarder\bin>
yes, I told UF to monitor the files with this command (on syslog host) but I never got any feedback output after executing the command, thats why I tried the list but it also gave no feedback/output:
splunk add monitor c:\kiwi\syslog
I think I did step 2 send data to splunk indexer. with my UF credentials file that I dloaded inside my cloud instance, yes
Not sure about step 3, the port (i forget which one) that the installer asked me for? i have to do something in the cloud instance too?
so it is a cloud instance?
is it the cloud trial?
can you access the search bar?
try and search index = _internal
and see if there is any data from the forwarder
check how many values, the host field has
did you tell the forwarder to monitor the files?
did you tell the forwarder to send the data to splunk indexer?
did you enable inputs (open ports) on your indexer?