Deployment Architecture

Splunk forwarder, instance, Sending log from my Linux installed on Hyper-v

ibztek
Loves-to-Learn Lots

I'm trying to send log from my Linux installed on Hyper-v windows into my Splunk instance and it data doesn't seem to reach it's destination. I have entered the port number in my Splunk instance - Receive data - configure receiving and entered my port number. i edited my input.conf file and why can't I see my log in Splunk???

Labels (1)
0 Karma

ibztek
Loves-to-Learn Lots

write now i am getting error when i try to ping splunkdeploy.customerscallnow.com: name or service not known..i seem to follow a prety nice instruction but i am not yet able to connect 

0 Karma

isoutamo
SplunkTrust
SplunkTrust
This error told that your DNS service cannot found it for that name. You should fix it first and then check if UF works after that.
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Check the contents of /opt/splunkforwarder/var/log/splunk/splunkd.log on your forwarder (especially the last entries in that log). That should show you whether it tried to connect to the indexer and if it did, why it failed.

0 Karma

ibztek
Loves-to-Learn Lots

it is tryiing to connect but it failes with name or service uknown

0 Karma

PickleRick
SplunkTrust
SplunkTrust

So either your outputs.conf in the forwarder point to a wrong server or you have DNS problems in your VM.

0 Karma

ibztek
Loves-to-Learn Lots
index=_internal host=<your UF node name + *> earliest=1

doesn't seem to reply anything.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could find your UF’s name from its $SPLUNK_HOME/var/log/splunk/splunkd.log. That log file contains also information if it can send it’s own logs to splunk server.

I assume that you have outputs.conf on place and it has defined your splunk server as a target?

0 Karma

ibztek
Loves-to-Learn Lots

iam trying to find my uf node name..im very new to splunk

0 Karma

ibztek
Loves-to-Learn Lots

i don't see my host in the splunk at all.

0 Karma

ibztek
Loves-to-Learn Lots

how can i do that, can you be a bit specific ? thank you

0 Karma

isoutamo
SplunkTrust
SplunkTrust

You could make a query on sh like 

index=_internal host=<your UF node name + *> earliest=1

this should show some entries, if your UF has connection to server. 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you see that your UF has sent its internal logs to server?

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...