Quantcast
Browsing all 1551 articles
Browse latest View live

What is the UF upgrade compatibility?

I need to upgrade a several forwarders that are running older versions such as 4.x and 5.x. to 7.x. Our distributed environment is running at 7.1.4. Do I need to upgrade the UF to 6.5.2 first? Or, can...

View Article


Splunk Universal Forwareder porformance impact

Hello. Do you know if exist a table, web page, benchmark or paper where the impact to performance for the appliances where an Universal Forwarder is installed on is shown?

View Article


How to install splunk app for linux without installing the universal forwarder?

Can I use splunk app for linux without installing universal forwarder on each linux host I need their logs?

View Article

New install of UF windows, splunkd.log says "sock_error = 10054. SSL Error =...

I just installed a new UF on a Windows VM, and I'm getting an error that connection to the host failed, with "sock_error = 10054. SSL Error = No error" The indexers I'm trying to connect to can talk to...

View Article

Monitor files perfomance

Hello, I need to monitor some Oracle Database agent logs with Splunk Universal Forwarder. The base directory for finding the logs is $ORACLE_HOME. We´re using this configuration to monitor these logs...

View Article


How to install Splunk UFD without asking for password in Linux?

HI Friends, I am installing Splunk UFD 7.2.5, but when I run the command (/opt/splunk/bin/splunk start --accept-license) its asking for the password. Is there a way I can install UFD without asking...

View Article

Log data of a particular sourcetype from one of the forwarder is missing in...

Hi All, In UF installed server ,we have monitor stanza to read the .log file from a particular source named it as one of the sourcetype. I used to get the log feed upto 7 days . But suddenly it stopped...

View Article

Why are there no logs received when the universal forwarder is sending data...

hello, i have a problem with the universal forwarder, i set up a universal forwarder to send to a search head splunk but i have not received any log

View Article


Why is indexed extraction not happening when the data comes via the UF?

Hi, We have a quite a "piggy backed" data coming from a system and extracting as [mysourcetype] SHOULD_LINEMERGE=false INDEXED_EXTRACTIONS=CSV FIELD_NAMES=Date,Time,EmployeeID,EmployeeName...

View Article


How to restart Universal Forwarder via the deployment server?

Hi Splunker Is There way to do restart for splunk agent via the deployment server by use a particular app or configuration? Please help me in that. Regards

View Article

What happens when we restart universal forwarder as root user ?

Hi All, So , What happens when I restart universal forwarder as root user on Linux . And Previously if done so what needs to be done if anything goes wrong I am missing one of the log file on a...

View Article

How to execute custom script on Universal Fowarder when Event Trigger Alert...

How to execute custom script on Universal Fowarder when Event Trigger Alert raised? I am monitoring my linux audit logs, upon receiving event from the remote client (UF), I want to trigger an event...

View Article

Significant sudden slowness in ingesting between servers with Splunk UF to...

Hi , Looking for an advice in troubleshooting the cause of the issue we are experiencing and how to solve it. We have few Splunk UF(s) where we are monitoring large amount of big files to our 4 load...

View Article


Why is there significant sudden slowness in ingesting between servers with...

Hi , Looking for an advice in troubleshooting the cause of the issue we are experiencing and how to solve it. We have few Splunk UF(s) where we are monitoring large amount of big files to our 4 load...

View Article

Why is my blacklist being so greedy when going through a Universal Forwarder?

I have an inputs.conf file that has multiple monitor stanzas and it appears that the blacklist used on one of the stanzas is being applied to all ... My aim is to have 4 sourcetypes for the same index...

View Article


Log file is no not shipping since being deleted

I had deleted a rouge log file which had become too large and caused the root partition to fill up. The log file has since been regenerated by the application and is now no longer shipping to spunk. I...

View Article

Spunk Windows TA + Windows Universal Forwarder vs clean Windows Universal...

Hi, There are any differences between Windows TA + Windows Universal Forwarder and clean Windows Universal forwarder installation? Could you please specify any?. Thank you in advamce

View Article


Is there a security reason to upgrade Splunk Universal Forwarder?

I subscribe to a RSS feed for Splunk CVEs and diligently keep my security team in the look regarding Splunk vulnerabilities. Since I've taken over the Splunk administrator role at my company, I've...

View Article

how to configure a universal forwarder on centos 7 ?

Hello, My problem is that the data I send with the forwarder does not reach splunk. Here is how I configured the forwarder First, I started the forwarder > ./splunk start in $Splunk_Home/bin>...

View Article

How to configure a universal forwarder on centos 7?

Hello, My problem is that the data I send with the forwarder does not reach splunk. Here is how I configured the forwarder First, I started the forwarder > ./splunk start in $Splunk_Home/bin>...

View Article
Browsing all 1551 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>