<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk UF in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-configure-Splunk-UF/m-p/627294#M15108</link>
    <description>&lt;P&gt;In Splunk Enterprise, go to Settings-&amp;gt;Forwarding and Receiving and enable receiving on port 9997.&amp;nbsp; No IP address assignments are necessary.&lt;/P&gt;&lt;P&gt;In the UF, configure the Splunk Enterprise address with the command&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./splunk add forward-server &amp;lt;&amp;lt;ip address&amp;gt;&amp;gt;:9997&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;or edit /opt/splunk/etc/system/local/outputs.conf&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout:group1]
server=&amp;lt;&amp;lt;ip address&amp;gt;&amp;gt;:9997&lt;/LI-CODE&gt;&lt;P&gt;and restart the UF.&lt;/P&gt;&lt;P&gt;See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.0.3/Forwarder/Configuretheuniversalforwarder" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.0.3/Forwarder/Configuretheuniversalforwarder&lt;/A&gt;&amp;nbsp;for more information about configuring the UF.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jan 2023 23:39:25 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2023-01-16T23:39:25Z</dc:date>
    <item>
      <title>How to configure Splunk UF?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-configure-Splunk-UF/m-p/627292#M15107</link>
      <description>&lt;P&gt;Splunk UF&lt;/P&gt;
&lt;P&gt;Hi folks,&lt;BR /&gt;Seeking help I am new to splunk I am trying to configure splunk UF, I have two vm's both vm's installed windows 10 however both vm's are communicating with each other in one VM I installed Splunk enterprise and in another VM installed Splunk UF.. Assuming splunk enterprise VM is receiver and splunk UF VM is forwarder so I assigned splunk UF VM IP into splunk enterprise VM as a forwader with port 9997 ex: xx.xx.xxx:9997&lt;BR /&gt;Still not receiving any logs from UF vm I would like to know that procedure I am doing is it correct&lt;BR /&gt;Would be appreciate your kind support&lt;BR /&gt;Thanks in advance..&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 17:14:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-configure-Splunk-UF/m-p/627292#M15107</guid>
      <dc:creator>Shakeer_Spl</dc:creator>
      <dc:date>2023-01-18T17:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-configure-Splunk-UF/m-p/627294#M15108</link>
      <description>&lt;P&gt;In Splunk Enterprise, go to Settings-&amp;gt;Forwarding and Receiving and enable receiving on port 9997.&amp;nbsp; No IP address assignments are necessary.&lt;/P&gt;&lt;P&gt;In the UF, configure the Splunk Enterprise address with the command&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./splunk add forward-server &amp;lt;&amp;lt;ip address&amp;gt;&amp;gt;:9997&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;or edit /opt/splunk/etc/system/local/outputs.conf&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[tcpout:group1]
server=&amp;lt;&amp;lt;ip address&amp;gt;&amp;gt;:9997&lt;/LI-CODE&gt;&lt;P&gt;and restart the UF.&lt;/P&gt;&lt;P&gt;See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.0.3/Forwarder/Configuretheuniversalforwarder" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.0.3/Forwarder/Configuretheuniversalforwarder&lt;/A&gt;&amp;nbsp;for more information about configuring the UF.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 23:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-configure-Splunk-UF/m-p/627294#M15108</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-01-16T23:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk UF</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-configure-Splunk-UF/m-p/627526#M15142</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;issue fixed there was problem with port 9997 reconfigured working fine.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 21:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-configure-Splunk-UF/m-p/627526#M15142</guid>
      <dc:creator>Shakeer_Spl</dc:creator>
      <dc:date>2023-01-18T21:19:06Z</dc:date>
    </item>
  </channel>
</rss>

