Splunk Cloud Platform

I can't see the event logs on splunk server from linux forwarder even though I setup the universal forwarder

Kendrick
Observer

I can't see the events log when I searching on splunk enterprise server. But I already check the splunk server status is running and I created the index = linux_universal_forwarder and host = linux_uf_1 into inputs.confg on forwarder linux machine. And I also created the receiving new port 8889 and new index = linux_universal_forwarder on splunk server. Why I can't see the logs ? I can able to ping between indexer and forwarder. Pls help how to fix this issue? how to troubleshoot step by step? I'm beginner to learn the Splunk. Thank you.

Kendrick_0-1690089343692.pngKendrick_1-1690089364076.png

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You have an established connection between the forwarder and the indexer on port 9997 so there's no need for port 8889.

The search query (index=_internal ...) should be entered in the Splunk UI (use the "Search & Reporting" app).

The add monitor command is entered in the CLI, but the "/path/to/app/logs" argument is a placeholder (like "foo") that must be replaced by the actual file to file you wish to monitor.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...