Splunk Search

Universal Forwarder in AIX system not sending any data to splunk server, how to configure universal forwarder in AIX?

etaga
New Member

I installed and configured Universal Forwarder in AIX but it does not send data to splunk server. I configured index in splunk server and add it to Universal Forwarder (inputs.conf) but the problem continue.

Tags (1)
0 Karma

etaga
New Member

I resolved it, was necessary to activate deploy in AIX. Now I have another problem. I configured only 3 hosts like forwarders but in App > Search&Reporting > Data Summary I find more hosts, some of them are not configured like forwarders. Why is possible that one host send logs to splunk when forwarders is not configured in it?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Did you configure outputs.conf and inputs.conf? You need to make sure that:

  1. The files that you want are being monitored by Splunk (inputs.conf)
  2. The data has a path to travel to the indexers (outputs.conf)

See these references:

http://www.splunk.com/base/Documentation/latest/Admin/Inputsconf?r=splunky
http://www.splunk.com/base/Documentation/latest/Admin/Outputsconf?r=splunky

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...