<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: macOS UnifiedForwarder in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705047#M20901</link>
    <description>&lt;P&gt;Look at the local splunkd.log file to see any connection attempts to the destination IP.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2024 15:04:29 GMT</pubDate>
    <dc:creator>dural_yyz</dc:creator>
    <dc:date>2024-11-22T15:04:29Z</dc:date>
    <item>
      <title>macOS Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705025#M20893</link>
      <description>&lt;P&gt;Hello everyone! I need help/hint: I tried to set up log forwarding from MacOS (ARM) to Splunk, but the logs never arrived. I followed the instructions from this &lt;A href="https://youtu.be/rs6q28xUd-o?si=1fkEZEo-1m2xmx8s" target="_self"&gt;video&lt;/A&gt;, and also installed and configured Add-on for Unix and Linux. And what index will they appear in? Thanks!&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Inside /Applications/SplunkForwarder&lt;/SPAN&gt;&lt;SPAN class=""&gt;/etc/system/local i have:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;inputs.conf, outputs.conf, server.conf.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;inputs.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[monitor:///var/log/system.log]
disabled = 0&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;outputs.conf&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[tcpout:default-autolb-group]
server = ip:9997
compressed = true

[tcpout-server://ip:9997]&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;server.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[general]
serverName = 
pass4SymmKey = 

[sslConfig]
sslPassword = 

[lmpool:auto_generated_pool_forwarder]
description = auto_generated_pool_forwarder
peers = *
quota = MAX
stack_id = forwarder

[lmpool:auto_generated_pool_free]
description = auto_generated_pool_free
peers = *
quota = MAX
stack_id = free&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 22:58:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705025#M20893</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-11-22T22:58:25Z</dc:date>
    </item>
    <item>
      <title>Re: macOS UnifiedForwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705047#M20901</link>
      <description>&lt;P&gt;Look at the local splunkd.log file to see any connection attempts to the destination IP.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 15:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705047#M20901</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-11-22T15:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: macOS UnifiedForwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705049#M20902</link>
      <description>&lt;P class=""&gt;&lt;SPAN class=""&gt;WARN&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;TcpOutputProc [22637 parsing] - The TCP output processor has paused the data flow. Forwarding to host_dest=ip&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;inside output group default-autolb-group from host_src=&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;has been blocked for blocked_seconds=16061. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;ERROR TcpOutputFd [22638 TcpOutEloop] - Read error. Connection reset by peer&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;It turns out there is no network interaction between the workstation and the splunk?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 15:08:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705049#M20902</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-11-22T15:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: macOS UnifiedForwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705058#M20905</link>
      <description>&lt;P&gt;Here we go.&amp;nbsp; So this could be network transmissions so check for firewall blocks and any routing issues first.&amp;nbsp; Then look into SSL connection issues last.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 15:43:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/macOS-Universal-Forwarder/m-p/705058#M20905</guid>
      <dc:creator>dural_yyz</dc:creator>
      <dc:date>2024-11-22T15:43:31Z</dc:date>
    </item>
  </channel>
</rss>

