<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Receiver not receiving data from universal forwarder in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46031#M8697</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm trying to congfigure a forwarder and the receiver doesn't get any data. Please help.&lt;/P&gt;

&lt;P&gt;Forwarder's outputs.conf:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = vm1.sandbox:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://vm1.sandbox:9997]&lt;/P&gt;

&lt;P&gt;That was configured using splunk add forward-server command.&lt;/P&gt;

&lt;P&gt;Below is the Receivers inputs.conf (configured via Splunk Web&amp;gt;Manager&amp;gt;Forwarding and receiving menu)&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;BR /&gt;
connection_host = ip&lt;/P&gt;

&lt;P&gt;Totally a newbie and trying to understand how these components work.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Fri, 24 May 2013 19:40:01 GMT</pubDate>
    <dc:creator>easedilctl</dc:creator>
    <dc:date>2013-05-24T19:40:01Z</dc:date>
    <item>
      <title>Receiver not receiving data from universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46031#M8697</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm trying to congfigure a forwarder and the receiver doesn't get any data. Please help.&lt;/P&gt;

&lt;P&gt;Forwarder's outputs.conf:&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = vm1.sandbox:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://vm1.sandbox:9997]&lt;/P&gt;

&lt;P&gt;That was configured using splunk add forward-server command.&lt;/P&gt;

&lt;P&gt;Below is the Receivers inputs.conf (configured via Splunk Web&amp;gt;Manager&amp;gt;Forwarding and receiving menu)&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;BR /&gt;
connection_host = ip&lt;/P&gt;

&lt;P&gt;Totally a newbie and trying to understand how these components work.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2013 19:40:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46031#M8697</guid>
      <dc:creator>easedilctl</dc:creator>
      <dc:date>2013-05-24T19:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Receiver not receiving data from universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46032#M8698</link>
      <description>&lt;P&gt;Did you configure inputs on the forwarder?&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2013 19:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46032#M8698</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-05-24T19:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Receiver not receiving data from universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46033#M8699</link>
      <description>&lt;P&gt;What is in your inputs.conf file on the forwarder?&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2013 19:53:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46033#M8699</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-05-24T19:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Receiver not receiving data from universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46034#M8700</link>
      <description>&lt;P&gt;The following is what's on my inputs.conf in the forwarder:&lt;/P&gt;

&lt;P&gt;[monitor:///opt/app/oracle/diag/rdbms/vm2db/vm2db/trace]&lt;/P&gt;

&lt;P&gt;And yes, splunk user has permissions on those directories.&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2013 20:27:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46034#M8700</guid>
      <dc:creator>easedilctl</dc:creator>
      <dc:date>2013-05-24T20:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: Receiver not receiving data from universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46035#M8701</link>
      <description>&lt;P&gt;Here is a great article on the Splunk wiki: &lt;A href="http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs"&gt;Troubleshooting Monitor Inputs&lt;/A&gt;&lt;BR /&gt;
i suggest that you skip the first part of the page on setting DEBUG mode, as the other suggestions on the page are generally both easier and more useful.&lt;/P&gt;

&lt;P&gt;And as a very first step, I would log onto the forwarder and give the following command&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk list monitor
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;which will tell you which files Splunk is reading. A quick peek at splunkd.log may be helpful, too; you can even search it with the following command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal source=*splunkd.log
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 24 May 2013 22:49:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46035#M8701</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-05-24T22:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: Receiver not receiving data from universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46036#M8702</link>
      <description>&lt;P&gt;not sure what happened but I started seeing the logs after rebooting the server. here's the output of spunk list monitor command&lt;/P&gt;

&lt;P&gt;Monitored Directories:&lt;BR /&gt;
    $SPLUNK_HOME/var/log/splunk/splunkd.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/audit.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/first_install.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/license_audit.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/license_usage.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/metrics.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/scheduler.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/searchhistory.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/splunkd.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/splunkd_access.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/splunkd_stderr.log&lt;BR /&gt;
        /opt/app/splunkforwarder/var/log/splunk/splunkd_stdout.log&lt;BR /&gt;
    $SPLUNK_HOME/var/spool/splunk/...stash_new&lt;BR /&gt;
    /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/alert_vm2db.log&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_dbrm_18753.trc&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_dbrm_18753.trm&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_j001_18973.trc&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_j001_18973.trm&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_mmon_18771.trc&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_mmon_18771.trm&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_vkrm_18831.trc&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_vkrm_18831.trm&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_vktm_18745.trc&lt;BR /&gt;
        /opt/app/oracle/diag/rdbms/vm2db/vm2db/trace/vm2db_vktm_18745.trm&lt;BR /&gt;
Monitored Files:&lt;BR /&gt;
    $SPLUNK_HOME/etc/splunk.version&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:00:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46036#M8702</guid>
      <dc:creator>easedilctl</dc:creator>
      <dc:date>2020-09-28T14:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: Receiver not receiving data from universal forwarder</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46037#M8703</link>
      <description>&lt;P&gt;thank you for your help!&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2013 19:37:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Receiver-not-receiving-data-from-universal-forwarder/m-p/46037#M8703</guid>
      <dc:creator>easedilctl</dc:creator>
      <dc:date>2013-05-29T19:37:46Z</dc:date>
    </item>
  </channel>
</rss>

