Installation

UF installation issues

greglousteau
New Member

I have a syslog server running on my LAN and multiple devices logging to it. I tried installing the UF onto this host (Win 10 VM), but I'm not seeing any data appear in my Splunk Cloud Instance, nor am I getting any output from this command on the Win10 syslog host?

Any guidance would be apprecaited

C:\Program Files\SplunkUniversalForwarder\bin>splunk list monitor

C:\Program Files\SplunkUniversalForwarder\bin>

Tags (1)
0 Karma

greglousteau
New Member

yes, I told UF to monitor the files with this command (on syslog host) but I never got any feedback output after executing the command, thats why I tried the list but it also gave no feedback/output:
splunk add monitor c:\kiwi\syslog

I think I did step 2 send data to splunk indexer. with my UF credentials file that I dloaded inside my cloud instance, yes

Not sure about step 3, the port (i forget which one) that the installer asked me for? i have to do something in the cloud instance too?

0 Karma

adonio
Ultra Champion

so it is a cloud instance?
is it the cloud trial?
can you access the search bar?
try and search index = _internal and see if there is any data from the forwarder
check how many values, the host field has

0 Karma

adonio
Ultra Champion

did you tell the forwarder to monitor the files?
did you tell the forwarder to send the data to splunk indexer?
did you enable inputs (open ports) on your indexer?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...