Deployment Architecture

Unable to add windows forwarder to cloud trial

elan_tech
New Member

Hi,

I've just started a trial of Splunk Cloud and have followed the instructions on how to add a forwarder on Windows including registering the credentials package and restarting the service however the cloud instance does not see the forwarder. local Windows firewall is off, network firewall is not blocking the traffic so network should be fine. The only thing ins the log is

06-13-2019 10:08:49.355 +0100 INFO ProxyConfig - Failed to initialize http_proxy from server.conf for splunkd. Please make sure that the http_proxy property is set as http_proxy=http://host:port in case HTTP proxying needs to be enabled.

The server.conf file doesn't include any proxy information and we do not use any proxy on our network.

Any advice please. thank you

Tags (2)
0 Karma

broberg
Communicator

Did you follow the guide you found from the cloud instance so you get the correct certificate?

0 Karma

elan_tech
New Member

I believe so, the guide that opened when i clicked on the installation instructions from my cloud instance was the following:

https://docs.splunk.com/Documentation/SplunkCloud/7.0.2/User/ForwardDataToSplunkCloudFromWindows

The only thing i would say is in step 2 i had to enter a username and password for the local account, so once installed there was no default username and password of admin:changeme as per the instructions.

I've tried this installation the same way on three Windows 10 PC's now and none of them are forwarding data.

0 Karma
Get Updates on the Splunk Community!

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...