Splunk Enterprise

Splunk Light - Cannot add data

1barrykemble
New Member

Hi,

I have followed the installation and configuration guide to get Splunk Light working and now I am at the point of adding a data source.

I get the same generic messsage (see screenshot) when I try to add a forwarder or setup syslog via the Monitor button.

There a lot of posts around about roles but as this is Splunk Light you only have the admin role to work with.

Am I missing something obvious?

Thanks,

alt text

Tags (1)
0 Karma

ChrisG
Splunk Employee
Splunk Employee

From your screen shot, it does not look as if you are using Splunk Light. At the upper left corner, you should see a Splunk Light logo in orange. Is it possible you have an Enterprise trial or free license active?

Splunk Light logo

andrewb_splunk
Splunk Employee
Splunk Employee

Based on the error message, this does seem to be a matter of your role not having the necessary permissions to add data to the instance. Sorry if this is a basic question, but are you sure you are using Splunk Light? The screen shot appears to be Splunk Enterprise.

1barrykemble
New Member

Yes that does look like the full Package, I will deploy again and see what happens.

Thanks,

Barry.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...