Hello all, I can't seem to get the windows universal forwarder to forward data.
- Splunk indexer (7.x.x) is on CentOS7, 8089 and 9997 open on firewall
- Latest Splunk forwarder installed on windows 10
- Did not go into customize on windows installer GUI, but did put the win event stanza from documentation into the forwarder inputs.conf (system local).
- opened 9997 data input in webui
- Turned off windows firewall for troubleshooting.
- Downloaded various windows apps/add-ons to splunk indexer thinking it was a deployment thing
What am I missing?
↧