Installation

what command do i use to point Splunk universal forwarder to my Splunk all in one instance or (HF)

MorgenHepton
Observer

I have used Splunk to threat hunt many times and have aspirations to build a distributed Splunk instance in the feature. I decided to start learning the installation, configuration, and deployment process of Splunk, by building a standalone instance. I get to a point where I think I have completed all the steps necessary to have a functioning Splunk set up. (connections are established on 8089 and 9997) and my web page is good. As soon as my apps are pushed to my (client)  this is when Splunk starts throwing an error stating indexers and ques are full. it also appears I am getting no logs from my applications. Any help is greatly appreciated. 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @MorgenHepton,

could you share your error?

are you receiving Splunk internal logs?

you can check this running a simple search              index=_internal host=<your_host>

what is you architecture? I understood that you have an stand-alone Splunk server (an all-in-one installation) and a Universal Forwarder (in a different system) that sgould send logs to the stand-alone system, is it correct?

running a telnet on the UF on ports 9997 and 8089 can you reach to connect the stand-alone server?

Ciao.

Giuseppe

0 Karma

MorgenHepton
Observer

thankyou for the reply.

The errors Im getting are all under splunkd

errors include

[tcpoutautolb-0, file monitor input, ingestion latency, real-time reader-0, and more.] 

sadly I did not save my errors before I decided to delete the Splunk instances and try and reinstall.

I believe I was receiving logs in the index _internal.

 

 

My deployment looks like this

(splunk all-in- on (redhat linux))-------------------(S.U.F (rocky linux))

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @MorgenHepton,

did you configured your UF to send logs to te Indexer?

for more infos see at https://docs.splunk.com/Documentation/Forwarder/9.2.0/Forwarder/Configuretheuniversalforwarder

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...