<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk App for Infrastructure - forwarder issue in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379807#M46209</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;
I've installed splunk app for Infrastructure on my local PC with Windows10 and want to collect local metrics and logs in this app.&lt;BR /&gt;
When I configure my local pc as entity I get to a point where a can copy/paste a script in powershell.&lt;/P&gt;

&lt;P&gt;When I do so a get:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[*] Install Splunk Universal Forwarder on localhost
[*] indexer server: localhost:9997
[*] checking for previous installations of splunk&amp;gt;...
[!] install directory already exists. continuing to congure ..
Test-Connection : Testing connection to computer 'KR9162NBN' failed: Unknown error (0x2b2a)
At C:\WINDOWS\system32\install_uf_script.ps1:174 char:12
+ $ip_info = Test-Connection -ComputerName $env:computername -count 1 | ...
+            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : ResourceUnavailable: (KR9162NBN:String) [Test-Connection], PingException
    + FullyQualifiedErrorId : TestConnectionException,Microsoft.PowerShell.Commands.TestConnectionCommand

[*] configuring metrics &amp;amp; log inputs...
[*] Restarting splunk&amp;gt; universal fowarder
SplunkForwarder: Stopped

Splunk&amp;gt; Needle. Haystack. Found.

Checking prerequisites...
        Checking mgmt port [8090]: open
        Checking conf files for problems...
        Done
        Checking default conf files for edits...
        Validating installed files against hashes from 'C:\Program Files\SplunkUniversalForwarder\splunkforwarder-7.1.2-a0c72a66db66-windows-64-manifest'
        All installed files intact.
        Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...

SplunkForwarder: Starting (pid 22324)
Done

[*] splunk&amp;gt; successfully started.
[*] running clean up.
[*] clean up complete. Exiting...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I previusly had installed a forwarder, so the script uses the existing one, and tries to configure it to sens metrics and logs, but I get the above error and no entity is shown in the App.&lt;/P&gt;

&lt;P&gt;When I look at Monitoring Console -&amp;gt; Forwarders  I see that the forwarder is up and runing.&lt;/P&gt;

&lt;P&gt;Tried to uninstal and reinstal the forwarder - same issue.&lt;/P&gt;

&lt;P&gt;Any ideas? Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jul 2018 13:20:25 GMT</pubDate>
    <dc:creator>danielwysockiar</dc:creator>
    <dc:date>2018-07-30T13:20:25Z</dc:date>
    <item>
      <title>Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379807#M46209</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I've installed splunk app for Infrastructure on my local PC with Windows10 and want to collect local metrics and logs in this app.&lt;BR /&gt;
When I configure my local pc as entity I get to a point where a can copy/paste a script in powershell.&lt;/P&gt;

&lt;P&gt;When I do so a get:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[*] Install Splunk Universal Forwarder on localhost
[*] indexer server: localhost:9997
[*] checking for previous installations of splunk&amp;gt;...
[!] install directory already exists. continuing to congure ..
Test-Connection : Testing connection to computer 'KR9162NBN' failed: Unknown error (0x2b2a)
At C:\WINDOWS\system32\install_uf_script.ps1:174 char:12
+ $ip_info = Test-Connection -ComputerName $env:computername -count 1 | ...
+            ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    + CategoryInfo          : ResourceUnavailable: (KR9162NBN:String) [Test-Connection], PingException
    + FullyQualifiedErrorId : TestConnectionException,Microsoft.PowerShell.Commands.TestConnectionCommand

[*] configuring metrics &amp;amp; log inputs...
[*] Restarting splunk&amp;gt; universal fowarder
SplunkForwarder: Stopped

Splunk&amp;gt; Needle. Haystack. Found.

Checking prerequisites...
        Checking mgmt port [8090]: open
        Checking conf files for problems...
        Done
        Checking default conf files for edits...
        Validating installed files against hashes from 'C:\Program Files\SplunkUniversalForwarder\splunkforwarder-7.1.2-a0c72a66db66-windows-64-manifest'
        All installed files intact.
        Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...

SplunkForwarder: Starting (pid 22324)
Done

[*] splunk&amp;gt; successfully started.
[*] running clean up.
[*] clean up complete. Exiting...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I previusly had installed a forwarder, so the script uses the existing one, and tries to configure it to sens metrics and logs, but I get the above error and no entity is shown in the App.&lt;/P&gt;

&lt;P&gt;When I look at Monitoring Console -&amp;gt; Forwarders  I see that the forwarder is up and runing.&lt;/P&gt;

&lt;P&gt;Tried to uninstal and reinstal the forwarder - same issue.&lt;/P&gt;

&lt;P&gt;Any ideas? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 13:20:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379807#M46209</guid>
      <dc:creator>danielwysockiar</dc:creator>
      <dc:date>2018-07-30T13:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379808#M46210</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
Seems like Test-Connection failed to get ip_info which is added as dimension. It should still work.&lt;/P&gt;

&lt;P&gt;Could you please check: 'SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\outputs.conf'. Check if your 'server =  ...' setting is correct and you can ping the server.&lt;/P&gt;

&lt;P&gt;Also, Can you post your inputs.conf file?  'SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\inputs.conf'&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 17:52:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379808#M46210</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2018-07-30T17:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379809#M46211</link>
      <description>&lt;P&gt;so the outputs.conf file&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = localhost:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and i get:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ping localhost

Pinging **** [::1] with 32 bytes of data:
General failure.
General failure.
General failure.
General failure.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and the inputs.conf file&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# *** Configure Metrics &amp;amp; Logs collected ***
[perfmon://CPU Load]
counters = % C1 Time;% C2 Time;% Idle Time;% Processor Time;% User Time;% Privileged Time;% Reserved Time;% Interrupt Time
instances = *
interval = 30
object = Processor
index = em_metrics
_meta =  os::"Microsoft Windows 10 Pro" os_version::10.0.16299 ip::"" entity_type::Windows_Host


[perfmon://Physical Disk]
counters = % Disk Read Time;% Disk Write Time
instances = *
interval = 30
object = PhysicalDisk
index = em_metrics
_meta =  os::"Microsoft Windows 10 Pro" os_version::10.0.16299 ip::"" entity_type::Windows_Host


[perfmon://Network Interface]
counters = Bytes Received/sec;Bytes Sent/sec;Packets Received/sec;Packets Sent/sec;Packets Received Errors;Packets Outbound Errors
instances = *
interval = 30
object = Network Interface
index = em_metrics
_meta =  os::"Microsoft Windows 10 Pro" os_version::10.0.16299 ip::"" entity_type::Windows_Host


[perfmon://Available Memory]
counters = Cache Bytes;% Committed Bytes In Use;Page Reads/sec;Pages Input/sec;Pages Output/sec;Committed Bytes;Available Bytes
interval = 30
object = Memory
index = em_metrics
_meta =  os::"Microsoft Windows 10 Pro" os_version::10.0.16299 ip::"" entity_type::Windows_Host
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 30 Jul 2018 19:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379809#M46211</guid>
      <dc:creator>danielwysockiar</dc:creator>
      <dc:date>2018-07-30T19:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379810#M46212</link>
      <description>&lt;P&gt;You ran the install script as an administrator, right?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 19:25:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379810#M46212</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2018-07-30T19:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379811#M46213</link>
      <description>&lt;P&gt;It seems you might have issue with your Windows system. If I google "ping localhost general failure", I can see many results with solutions to fix it. You might have to try that to fix it. Let me know if it still doesn't work. &lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 19:39:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379811#M46213</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2018-07-30T19:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379812#M46214</link>
      <description>&lt;P&gt;Yeah, I'm trying to figure right now what is going on&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 19:45:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379812#M46214</guid>
      <dc:creator>danielwysockiar</dc:creator>
      <dc:date>2018-07-30T19:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379813#M46215</link>
      <description>&lt;P&gt;Are all of the required ports open and accessible on your Splunk Insight instance? No firewall or network restrictions&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jul 2018 21:25:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379813#M46215</guid>
      <dc:creator>ntankersley_spl</dc:creator>
      <dc:date>2018-07-30T21:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379814#M46216</link>
      <description>&lt;P&gt;Yes they are. &lt;BR /&gt;
I've done some researching and managed to ping 127.0.0.1.&lt;BR /&gt;
Done testing:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;PS C:\WINDOWS\system32&amp;gt; Test-NetConnection -ComputerName 127.0.0.1 -Port 9997


ComputerName     : 127.0.0.1
RemoteAddress    : 127.0.0.1
RemotePort       : 9997
InterfaceAlias   : Loopback Pseudo-Interface 1
SourceAddress    : 127.0.0.1
TcpTestSucceeded : True
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;outputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = 127.0.0.1:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Still no Entities visible.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 08:23:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379814#M46216</guid>
      <dc:creator>danielwysockiar</dc:creator>
      <dc:date>2018-07-31T08:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379815#M46217</link>
      <description>&lt;P&gt;Could you try this CLI command and see if you have any active forwards?&lt;BR /&gt;
Go to C:\Program Files\SplunkUniversalForwarder\bin and do&lt;BR /&gt;
".\splunk list forward-server" &lt;/P&gt;

&lt;P&gt;If you don't have any user account created. You can follow this to create an account:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.1.2/Installation/StartSplunkforthefirsttime"&gt;https://docs.splunk.com/Documentation/Splunk/7.1.2/Installation/StartSplunkforthefirsttime&lt;/A&gt;&lt;BR /&gt;
"Create administrator credentials manually"&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jul 2018 18:12:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379815#M46217</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2018-07-31T18:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379816#M46218</link>
      <description>&lt;P&gt;Got an active one as localhost:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    PS C:\Program Files\SplunkUniversalForwarder\bin&amp;gt; ./splunk list forward-server
    Active forwards:
            localhost:9997
    Configured but inactive forwards:
            None
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 01 Aug 2018 07:06:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379816#M46218</guid>
      <dc:creator>danielwysockiar</dc:creator>
      <dc:date>2018-08-01T07:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379817#M46219</link>
      <description>&lt;P&gt;Just a thought, maybe It has something to do with the field &lt;EM&gt;hostname&lt;/EM&gt;.&lt;/P&gt;

&lt;P&gt;I searched the index=_internal and splunk found a field host=xxx&lt;/P&gt;

&lt;P&gt;The forwarder on the other hand sends data to 127.0.0.1:9997&lt;BR /&gt;
outputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [tcpout]
 defaultGroup = default-autolb-group

 [tcpout:default-autolb-group]
 server = 127.0.0.1:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Checked the indexer:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\Splunk\bin&amp;gt;splunk display listen
Receiving is enabled on port 9997.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Checked theforwarder again:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\bin&amp;gt;splunk list forward-server
Active forwards:
        localhost:9997
Configured but inactive forwards:
        None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;also checked on the indexer splunkd.log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;07-31-2018 10:03:34.311 +0200 INFO  TcpOutputProc - Connected to idx=127.0.0.1:9997, pset=0, reuse=0.
07-31-2018 10:03:40.892 +0200 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::configure: Failed to find Event Log with channel name='Forwarded Events'
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;on forwarder:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\bin&amp;gt;splunk show default-hostname
    Default hostname for data inputs: xxx.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;on receiver GUI:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd component=TcpInputConfig OR (host=xxx component=StatusMgr)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;gives zero events&lt;/P&gt;</description>
      <pubDate>Wed, 01 Aug 2018 12:05:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379817#M46219</guid>
      <dc:creator>danielwysockiar</dc:creator>
      <dc:date>2018-08-01T12:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379818#M46220</link>
      <description>&lt;P&gt;I think hostname should not be a problem. You can change it using:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/154999/how-can-i-change-the-default-hostname-in-splunk.html" target="_blank"&gt;https://answers.splunk.com/answers/154999/how-can-i-change-the-default-hostname-in-splunk.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Can I see your props and transforms.conf file located in etc\apps\splunk_app_infrastructure\default\  ?&lt;/P&gt;

&lt;P&gt;ALso, Can you try this search:&lt;/P&gt;

&lt;P&gt;| mstats count where host=* AND metric_name=* by index,host,metric_name&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379818#M46220</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2020-09-29T20:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379819#M46221</link>
      <description>&lt;P&gt;Here you go:&lt;BR /&gt;
transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;########### Entity Store #################
[em_entities]
external_type = kvstore
collection = em_entities
fields_list = _key,title,state,dimensions,identifier_dimensions,informational_dimensions,imported_date,updated_date, collectors

[em_collector_configs]
external_type = kvstore
collection = em_collector_configs
fields_list = _key,name,title,source_predicate,title_dimension,identifier_dimensions,informational_dimensions,blacklisted_dimensions,monitoring_frequency,monitoring_lag,monitoring_calculation_window,disabled,vital_metrics

[em_groups]
external_type = kvstore
collection = em_groups
fields_list = _key, name, title, filter

[em_thresholds]
external_type = kvstore
collection = em_thresholds
fields_list = _key, name, type_id, type, metric_name, info_min, info_max, warning_min, warning_max, critical_min, critical_max, email_enabled, email_to, email_when

########### Metrics ######################
[metrics-hostoverride]
DEST_KEY = MetaData:Host
REGEX = host=(\S+)
FORMAT = host::$1

########### Transforms for Windows ######################
[value]
REGEX = .*Value=(\S+).*
FORMAT = _value::$1
WRITE_META = true

# Example: object=PhysicalDisk counter="%_Disk_Write_Time"
# Transform - metric_name::PhysicalDisk.%_Disk_Write_Time
[perfmon_metric_name]
REGEX = .*object=(\S+).*counter=(\S+).*
FORMAT = metric_name::$1.$2 metric_type::$1
WRITE_META = true

[instance]
REGEX = .*instance=(\S+).*
FORMAT = instance::$1
WRITE_META = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;as for the "mstats" command, zero results&lt;/P&gt;

&lt;P&gt;Checked also Settings -&amp;gt; indexes to find out if there are any metrics indexes, and there is the only one: "em_metrics" assigned to "splunk_app_infrastructure with 0 event count&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379819#M46221</guid>
      <dc:creator>danielwysockiar</dc:creator>
      <dc:date>2020-09-29T20:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379820#M46222</link>
      <description>&lt;P&gt;if you are an existing Splunk customer please file a support case so we can pick up some more details about your environment.&lt;/P&gt;

&lt;P&gt;Have you tried these troubleshooting docs ?:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/Troubleshooting/AdvancedWindowsTroubleshooting"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/Troubleshooting/AdvancedWindowsTroubleshooting&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2018 18:56:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379820#M46222</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2018-08-02T18:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379821#M46223</link>
      <description>&lt;P&gt;Hi, I'll have to have a closer look on those troubleshootig docs.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 12:03:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379821#M46223</guid>
      <dc:creator>danielwysockiar</dc:creator>
      <dc:date>2018-08-07T12:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Infrastructure - forwarder issue</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379822#M46224</link>
      <description>&lt;P&gt;you can all try to uninstall completely and reinstall  Splunk Universal Forwarder (using the powershell script on Add Data page)&lt;/P&gt;</description>
      <pubDate>Tue, 07 Aug 2018 21:37:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-App-for-Infrastructure-forwarder-issue/m-p/379822#M46224</guid>
      <dc:creator>dagarwal_splunk</dc:creator>
      <dc:date>2018-08-07T21:37:04Z</dc:date>
    </item>
  </channel>
</rss>

