Installation

what command do i use to point Splunk universal forwarder to my Splunk all in one instance or (HF)

MorgenHepton
Observer

I have used Splunk to threat hunt many times and have aspirations to build a distributed Splunk instance in the feature. I decided to start learning the installation, configuration, and deployment process of Splunk, by building a standalone instance. I get to a point where I think I have completed all the steps necessary to have a functioning Splunk set up. (connections are established on 8089 and 9997) and my web page is good. As soon as my apps are pushed to my (client)  this is when Splunk starts throwing an error stating indexers and ques are full. it also appears I am getting no logs from my applications. Any help is greatly appreciated. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @MorgenHepton,

could you share your error?

are you receiving Splunk internal logs?

you can check this running a simple search              index=_internal host=<your_host>

what is you architecture? I understood that you have an stand-alone Splunk server (an all-in-one installation) and a Universal Forwarder (in a different system) that sgould send logs to the stand-alone system, is it correct?

running a telnet on the UF on ports 9997 and 8089 can you reach to connect the stand-alone server?

Ciao.

Giuseppe

0 Karma

MorgenHepton
Observer

thankyou for the reply.

The errors Im getting are all under splunkd

errors include

[tcpoutautolb-0, file monitor input, ingestion latency, real-time reader-0, and more.] 

sadly I did not save my errors before I decided to delete the Splunk instances and try and reinstall.

I believe I was receiving logs in the index _internal.

 

 

My deployment looks like this

(splunk all-in- on (redhat linux))-------------------(S.U.F (rocky linux))

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @MorgenHepton,

did you configured your UF to send logs to te Indexer?

for more infos see at https://docs.splunk.com/Documentation/Forwarder/9.2.0/Forwarder/Configuretheuniversalforwarder

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...