Splunk Enterprise

Universal Forwarder Stanza

iherb_0718
Path Finder

Universal Forwarder installed on a Windows server using all default settings.

Where can I find the stanza that has the types of events it is logging so that I can validate it received th

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

No one stanza has that information.  The best way, IMO, to see what a UF is sending to the indexers is use btool.  On the server running the UF, run this CLI command:

C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe btool -debug inputs list

You will need the admin credentials you defined when you installed the forwarder.  It will then spit out a list of all of its input stanzas and associated settings.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No one stanza has that information.  The best way, IMO, to see what a UF is sending to the indexers is use btool.  On the server running the UF, run this CLI command:

C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe btool -debug inputs list

You will need the admin credentials you defined when you installed the forwarder.  It will then spit out a list of all of its input stanzas and associated settings.

---
If this reply helps you, Karma would be appreciated.
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @iherb_0718 

Open cmd line and navigate to %SPLUNK_HOME%\bin in Windows and execute the following command to find the input stanzas being configured by default.

 

splunk btool inputs list

 

---

An upvote would be appreciated and accept solution if it helps!

Tags (2)
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...