Splunk Enterprise

Splunk Light - Cannot add data

1barrykemble
New Member

Hi,

I have followed the installation and configuration guide to get Splunk Light working and now I am at the point of adding a data source.

I get the same generic messsage (see screenshot) when I try to add a forwarder or setup syslog via the Monitor button.

There a lot of posts around about roles but as this is Splunk Light you only have the admin role to work with.

Am I missing something obvious?

Thanks,

alt text

Tags (1)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

From your screen shot, it does not look as if you are using Splunk Light. At the upper left corner, you should see a Splunk Light logo in orange. Is it possible you have an Enterprise trial or free license active?

Splunk Light logo

andrewb_splunk
Splunk Employee
Splunk Employee

Based on the error message, this does seem to be a matter of your role not having the necessary permissions to add data to the instance. Sorry if this is a basic question, but are you sure you are using Splunk Light? The screen shot appears to be Splunk Enterprise.

1barrykemble
New Member

Yes that does look like the full Package, I will deploy again and see what happens.

Thanks,

Barry.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...