<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Receiving Data on Splunk Server in Security</title>
    <link>https://community.splunk.com/t5/Security/Receiving-Data-on-Splunk-Server/m-p/549801#M12208</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233978"&gt;@AmyShah&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you're not receiving data from a Forwarder you have at first to check if you did all the configuration steps:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;put Indexer in receiving state [Settings -- Forwarding and Receiving -- Receive Data];&lt;/LI&gt;&lt;LI&gt;configure Forwarder to send data to that Indexers (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents&lt;/A&gt;), with final restart of the Forwarder;&lt;/LI&gt;&lt;LI&gt;be sure that the route between them is open (from Forwarder use telnet on the Indexer's 9997 port).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you did all the above configuration steps, you have to check, if you're receiving logs.&lt;/P&gt;&lt;P&gt;At first check if you're receiving the Splunk internal logs:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;your_host&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;If yes, the problem is that you have to configure inputs&amp;nbsp; (&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/Data/Usingapps" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/Data/Usingapps&lt;/A&gt;)&amp;nbsp;or there's a problem on them.&lt;/P&gt;&lt;P&gt;If not, check again the connection.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 29 Apr 2021 10:27:59 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-04-29T10:27:59Z</dc:date>
    <item>
      <title>Receiving Data on Splunk Server</title>
      <link>https://community.splunk.com/t5/Security/Receiving-Data-on-Splunk-Server/m-p/549799#M12207</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am unable to receive data from the forwarder to the server However I have added the server&lt;/P&gt;&lt;P&gt;on server I got&lt;/P&gt;&lt;P&gt;netstat -auntp | grep 9997&lt;/P&gt;&lt;P&gt;tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN&lt;BR /&gt;tcp 0 0 myserver:9997 ServerIP:60992 ESTABLISHED&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 10:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Receiving-Data-on-Splunk-Server/m-p/549799#M12207</guid>
      <dc:creator>AmyShah</dc:creator>
      <dc:date>2021-04-29T10:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Receiving Data on Splunk Server</title>
      <link>https://community.splunk.com/t5/Security/Receiving-Data-on-Splunk-Server/m-p/549801#M12208</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233978"&gt;@AmyShah&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you're not receiving data from a Forwarder you have at first to check if you did all the configuration steps:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;put Indexer in receiving state [Settings -- Forwarding and Receiving -- Receive Data];&lt;/LI&gt;&lt;LI&gt;configure Forwarder to send data to that Indexers (&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents&lt;/A&gt;), with final restart of the Forwarder;&lt;/LI&gt;&lt;LI&gt;be sure that the route between them is open (from Forwarder use telnet on the Indexer's 9997 port).&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If you did all the above configuration steps, you have to check, if you're receiving logs.&lt;/P&gt;&lt;P&gt;At first check if you're receiving the Splunk internal logs:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;your_host&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;If yes, the problem is that you have to configure inputs&amp;nbsp; (&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/Data/Usingapps" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/Data/Usingapps&lt;/A&gt;)&amp;nbsp;or there's a problem on them.&lt;/P&gt;&lt;P&gt;If not, check again the connection.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Apr 2021 10:27:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Receiving-Data-on-Splunk-Server/m-p/549801#M12208</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-04-29T10:27:59Z</dc:date>
    </item>
  </channel>
</rss>

