Monitoring Splunk

There are currently no forwarders configured as deployment clients to this instance



I have a splunk server that is on windows and a vmware that windows on it too for forwarding data from vmware to host system. I read documents and do it step by step to  install and configure the universal forwarder on vm . the ports for receiver on two machines are open with firewall rules. but when i add data to splunk server the message show "There are currently no forwarders configured as deployment clients to this instance" and i search more but not fixed. 

there are solution for this subject on this community but not work for me. please help. thanks.

Labels (2)
Tags (1)
0 Karma



couple of questions as I didn't get those from your question.

  • Are configured that UF as Deployment client for splunk server or just add it with local configurations?
  • Have you configure splunk server's monitoring console part and add forwarders monitoring there?
  • Have you gotten any internal logs from UF to server?
  • Can you share your UF's outputs.conf, inputs.conf, deploymentclient.conf and serverclass.conf from you server and UF?

r. Ismo 

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...