Splunk installs on the server and I run the following commands,
splunk edit user admin –password
At this point I get a message that says, "Your session is invalid. Please login."
I login and it appears to edit the admin account just fine.
Splunk set deploy-poll servername:8089
It appears to update the configuration and requests the service be restarted.
Splunk restart
Restarts the service and appears to be fine.
In reviewing the C:\Program Files\SplunkForwarder\etc\apps folder there are only 4 folders listed.
Splunk does not forward the events. Any ideas?
... View more