Splunk Enterprise

Universal Forwarder Stanza

iherb_0718
Path Finder

Universal Forwarder installed on a Windows server using all default settings.

Where can I find the stanza that has the types of events it is logging so that I can validate it received th

Labels (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

No one stanza has that information.  The best way, IMO, to see what a UF is sending to the indexers is use btool.  On the server running the UF, run this CLI command:

C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe btool -debug inputs list

You will need the admin credentials you defined when you installed the forwarder.  It will then spit out a list of all of its input stanzas and associated settings.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

No one stanza has that information.  The best way, IMO, to see what a UF is sending to the indexers is use btool.  On the server running the UF, run this CLI command:

C:\Program Files\SplunkUniversalForwarder\bin\splunk.exe btool -debug inputs list

You will need the admin credentials you defined when you installed the forwarder.  It will then spit out a list of all of its input stanzas and associated settings.

---
If this reply helps you, Karma would be appreciated.
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi @iherb_0718 

Open cmd line and navigate to %SPLUNK_HOME%\bin in Windows and execute the following command to find the input stanzas being configured by default.

 

splunk btool inputs list

 

---

An upvote would be appreciated and accept solution if it helps!

Tags (2)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) v3.54.0

The Splunk Threat Research Team (STRT) recently released Enterprise Security Content Update (ESCU) v3.54.0 and ...

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...