...iles to the folders where monitor command pointing to pickup the files, it is not forwarding events to the SPLUNK indexer since I cannot see those events within SPLUNK. However, when I t...
I am operating in an environment with a standalone Splunk Enterprise instance running v8.1.3 on RHEL. In my environment I have around 350 Universal Forwarders that have been up and running f...
Is there a way to find which forwarder a devices event logs came from. I have hundreds of devices sending WEC logs through WEC servers, I could really do with an easy method to pinpoint where they c...
Hello everyone, I hope you all are doing well. I have been tasked to update Splunk enterprise to the 8.2.1 version and the forwarders to 8.1.4. Does anyone know if this upgrade is going t...
hi all,
how can i send the same data from one universal forwarder to multiple universal forwarder ?
is there a way to configure this ? if yes, please tell me the process.
hi, i know many have answered this question before but i didn't find any perfect and detailed answer. Setup :- UF ---> HF -----> IDX Q1. i have a file called test.txt ( Location ...
hi again 🙂
after upgrading our 26 linux universal forwarders from 7.x to 8.2.5, one of them will not run anymore. it immediately shuts down itself after start. splunkd.log shows nothing s...
HI I have a web UI connection into the Heavy Forwarder over port 8000. Is there a way I can view a list of universal forwarders that are sending to this Heavy forwarder?
...ant to mess with IE as that would involve security and I would rather not point out this hole until after I have the forwarder downloaded and installed.
Hello community
Trying to figure out what is blocking/affecting UF on Windows
Agent was installed using CLI
msiexec.exe /i splunkforwarder-<version>-x64-release.msi DEPLOYMENT_SERVER="<...