I currently have a UniversalForwarder running on a linux syslog server with a bunch of file monitors in place such as: [monitor:///var/log/10.10.10.99/syslog.log]index=hphost_segment=3disabled=0 The...
Hi I need to update theUniversalForwarder credential package manually. Due to our configuration, I can't follow the steps out line here in this document. I unpacked the `.spl` file t...
I'm having some issues getting UniversalForwarders to talk to the Deployment Server, and I'm looking for some troubleshooting pointers. Here's the scenario, pretty basic setup.
Splunk E...
Hi All,
We are using Splunk Cloud and have a UniversalForwarder setup on a windows machine - it reads CSV files from a particular folder and sends to indexer.
inputs.conf:
&n...
Most of the time, we are seeing that the Splunk universalforwarder or heavy forwarder is failing to forward data to the indexer. In this scenario, what troubleshooting steps should we take to i...
A new custom app and index was created and successfully deployed to 37 clients, as seen in the Fowarder Management interface in my Deployment Server. However, I do not see any data when searching i...
When I try to add my indexer to the configuration of my linux box where I have installed theuniversalforwarder, it errors on authentication.
This is on Splunk 5.0, and the Splunk server (i...
I'm facing 1 issue when try to install a Splunk universalforwarder in one of my job sites. Every time when I change its connection to 127.0.0.1 51112, it will fail after 3 minutes of waiting and r...
...an you please share thetroubleshooting steps for theforwarder? Can forwarder log files help us pin point - if forwarder at all sending the events to Indexer?
...ave configured it to receive data via port 9997 through the "Forwarding and Receiving" settings page. I have installed a UniversalForwarder on another server. I added a forward-server (side note: C...