I have 2 universal forwarders pointing to 1 receiver. All are Windows 64.
I confirm that they are both "seen" by using the dashboard "Forwarders: Deployment" in Splunk Web on the receiver.
I don't know how to get the data into Splunk so it can be indexed. If I choose "data inputs" and choose one of the "forwarder" options, it just says "There are currently no forwarders configured as deployment clients to this instance".
↧