<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf. in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452311#M20566</link>
    <description>&lt;P&gt;Hi @ahmemohs03,&lt;/P&gt;

&lt;P&gt;So after the other comments think I know what part of the issue is...&lt;/P&gt;

&lt;P&gt;Splunk by default does not have the listening ports enabled i.e. 9997.  So you will need to edit the inputs.conf file and insert then restart splunkd:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunktcp://9997]
connection_host = dns
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note: By default Splunk will use "connection_host = ip" meaning that the "host" field will come up as the IP address and not use the DNS name...&lt;BR /&gt;&lt;BR /&gt;
Note 2: You could also use the command line to enable the listening port:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunk/bin/splunk enable listen 9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Confirm the configuration by the command line via:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunk/bin/splunk display listen
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Note: You will have to login but you should see the following line (or whatever port you enabled)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Receiving is enabled on port 9997.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The "X509Verify" message is more of a hint/tip that for enterprises or for production use, you should use a proper PKI solution (Certificates) either from a 3rd-party or if you have your own Certificate Service then use that.  As the Splunk CA is one that gets shipped out in every download and as such the communications aren't as secure...&lt;/P&gt;

&lt;P&gt;For in the logs on your Linux A system (Splunk Enterprise) you should see something similar to the below lines for the various port inputs usually after all of the "HotDBManager" &amp;amp; "IndexWriter" messages...&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;07-22-2018 12:49:57.748 +1000 INFO  TcpInputConfig - IPv4 port 517 is reserved for raw input
07-22-2018 12:49:57.748 +1000 INFO  TcpInputConfig - IPv4 port 517 will negotiate s2s protocol level 4
07-22-2018 12:49:57.748 +1000 INFO  TcpInputConfig - IPv4 port 9997 is reserved for splunk 2 splunk
07-22-2018 12:49:57.748 +1000 INFO  TcpInputConfig - IPv4 port 9997 will negotiate s2s protocol level 4
07-22-2018 12:49:57.754 +1000 INFO  TcpInputProc - Creating raw Acceptor for IPv4 port 514 with Non-SSL
07-22-2018 12:49:57.755 +1000 INFO  TcpInputProc - Creating raw Acceptor for IPv4 port 515 with Non-SSL
07-22-2018 12:49:57.768 +1000 INFO  TcpInputProc - Creating raw Acceptor for IPv4 port 516 with Non-SSL
07-22-2018 12:49:57.768 +1000 INFO  TcpInputProc - Creating raw Acceptor for IPv4 port 517 with Non-SSL
07-22-2018 12:49:57.768 +1000 INFO  TcpInputProc - Creating fwd data Acceptor for IPv4 port 9997 with Non-SSL
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;HR /&gt;

&lt;P&gt;Regarding the web GUI on Linux A, any configuration on Linux B will have zero effect upon this...  What I would say is confirm that the user that which Splunk is running under has permissions to open ports, or has ownership of the entire "/opt/splunk/" folder structure.&lt;/P&gt;

&lt;P&gt;For this would you mind sending in what your web.conf looks like, also check your splunkd.log for any errors, I believe if you look after the "TailReader" / "TailingProocessor" entries there should be couple items from "loader" talking about REST HTTP server, then two X509Verify entries...  If there are issues this is where it probably will mention what is causing the web gui from working.  Could possibly need to look at your mongod.log file as well to make sure that it starting correctly (esp. if you have changed the sslPassword setting within server.conf):&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;...
07-22-2018 12:50:05.910 +1000 INFO  TailingProcessor - Adding watch on path: /var/adm.
07-22-2018 12:50:05.910 +1000 INFO  TailingProcessor - Adding watch on path: /var/log.
07-22-2018 12:50:05.917 +1000 INFO  loader - Limiting REST HTTP server to 1365 sockets
07-22-2018 12:50:05.917 +1000 INFO  loader - Limiting REST HTTP server to 303 threads
07-22-2018 12:50:05.917 +1000 WARN  X509Verify - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts y
our Splunk instance at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: &amp;lt;http://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-
signcertificates&amp;gt;
07-22-2018 12:50:06.291 +1000 WARN  X509Verify - X509 certificate (O=SplunkUser,CN=splunk) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts your Splunk instan
ce at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: &amp;lt;http://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When you restart Splunk from the command line, I would recommend using the splunk binary instead of "systemctl" if that is what you are using as the "splunk" binary will provide some basic output on each stage... e.g.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Stopping splunk helpers...
                                                           [  OK  ]
Done.

Splunk&amp;gt; Like an F-18, bro.

Checking prerequisites...
        Checking http port [8000]: open
        Checking mgmt port [8089]: open
        Checking appserver port [127.0.0.1:8065]: open
        Checking kvstore port [8191]: open
        Checking configuration...  Done.
        Checking critical directories...        Done
        Checking indexes...
                Validated: _audit _internal _introspection _telemetry _thefishbucket add_on_builder_index car_data cim_modactions cim_summary firedalerts history main os os_metrics perfmon pos_pu sophos summary synology syslog unifi windows wineventlog
        Done
        Checking filesystem compatibility...  Done
        Checking conf files for problems...
        Done
        Checking default conf files for edits...
        Validating installed files against hashes from '/opt/splunk/splunk-7.1.0-2e75b3406c5b-linux-2.6-x86_64-manifest'
        All installed files intact.
        Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Done                                                           [  OK  ]
Waiting for web server at &lt;A href="https://127.0.0.1:8000" target="test_blank"&gt;https://127.0.0.1:8000&lt;/A&gt; to be available......................... Done

If you get stuck, we're here to help.
Look for answers here: &lt;A href="http://docs.splunk.com" target="test_blank"&gt;http://docs.splunk.com&lt;/A&gt;

The Splunk web interface is at &lt;A href="https://splunk:8000" target="test_blank"&gt;https://splunk:8000&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Sun, 22 Jul 2018 03:26:32 GMT</pubDate>
    <dc:creator>lmaclean</dc:creator>
    <dc:date>2018-07-22T03:26:32Z</dc:date>
    <item>
      <title>ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452282#M20537</link>
      <description>&lt;P&gt;07-18-2018 21:20:40.725 +0000 WARN  X509Verify - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts your Splunk instance at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: &lt;BR /&gt;
07-18-2018 21:20:40.736 +0000 INFO  WatchedFile - Will begin reading at offset=392049 for file='/welldata/splunk/var/log/introspection/disk_objects.log'.&lt;BR /&gt;
07-18-2018 21:20:40.740 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/welldata/splunk/var/log/introspection/http_event_collector_metrics.log'.&lt;BR /&gt;
07-18-2018 21:20:40.799 +0000 ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;BR /&gt;
07-18-2018 21:20:40.967 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/welldata/splunk/var/log/splunk/btool.log'.&lt;BR /&gt;
07-18-2018 21:20:40.970 +0000 INFO  WatchedFile - Will begin reading at offset=3894 for file='/welldata/splunk/var/log/splunk/splunkd-utility.log'.&lt;BR /&gt;
07-18-2018 21:20:40.977 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/welldata/splunk/var/log/splunk/searchhistory.log'.&lt;BR /&gt;
07-18-2018 21:20:40.981 +0000 INFO  WatchedFile - Will begin reading at offset=238867 for file='/welldata/splunk/var/log/splunk/splunkd_access.log'.&lt;BR /&gt;
07-18-2018 21:20:40.998 +0000 INFO  WatchedFile - Will begin reading at offset=3141787 for file='/welldata/splunk/var/log/splunk/audit.log'.&lt;BR /&gt;
07-18-2018 21:20:41.001 +0000 INFO  WatchedFile - Will begin reading at offset=933 for file='/welldata/splunk/var/log/splunk/conf.log'.&lt;BR /&gt;
07-18-2018 21:20:41.020 +0000 INFO  WatchedFile - Will begin reading at offset=2076287 for file='/welldata/splunk/var/log/splunk/health.log'.&lt;BR /&gt;
07-18-2018 21:20:43.337 +0000 INFO  IntrospectionGenerator:resource_usage -   RU_main - I-data gathering (Resource Usage) starting; period=10s&lt;BR /&gt;
07-18-2018 21:20:43.349 +0000 INFO  IntrospectionGenerator:resource_usage -   RU_main - I-data gathering (IO Statistics) starting; interval=60s&lt;BR /&gt;
07-18-2018 21:20:46.023 +0000 WARN  TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
07-18-2018 21:20:48.590 +0000 INFO  ExecProcessor - message from "python /welldata/splunk/etc/apps/splunk_monitoring_console/bin/dmc_config.py" Cannot detect SHC status because of License Restriction. Will not disable DMC.&lt;BR /&gt;
07-18-2018 21:21:10.392 +0000 INFO  ScheduledViewsReaper - Scheduled views reaper run complete. Reaped count=0 scheduled views&lt;BR /&gt;
07-18-2018 21:52:08.785 +0000 WARN  TcpInputProc - Stopping all listening ports. Queues blocked for more than 300 seconds&lt;BR /&gt;
07-18-2018 21:52:08.785 +0000 INFO  TcpInputProc - Stopping IPv4 port 9997&lt;BR /&gt;
07-18-2018 21:59:59.999 +0000 INFO  ExecProcessor - setting reschedule_ms=3600002, for command=python /welldata/splunk/etc/apps/splunk_instrumentation/bin/instrumentation.py&lt;BR /&gt;
07-18-2018 23:00:00.003 +0000 INFO  ExecProcessor - setting reschedule_ms=3599997, for command=python /welldata/splunk/etc/apps/splunk_instrumentation/bin/instrumentation.py&lt;BR /&gt;
07-19-2018 00:00:00.000 +0000 INFO  ExecProcessor - setting reschedule_ms=3600000, for command=python /welldata/splunk/etc/apps/splunk_instrumentation/bin/instrumentation.py&lt;BR /&gt;
07-19-2018 00:00:00.000 +0000 INFO  ExecProcessor - setting reschedule_ms=86400000, for command=python /welldata/splunk/etc/apps/splunk_instrumentation/bin/schedule_delete.py&lt;BR /&gt;
07-19-2018 00:00:00.945 +0000 INFO  LMStackMgr - should rollover=true because _lastRolloverTime=1531872000 lastRolloverDay=1531872000 snappedNow=1531958400&lt;BR /&gt;
07-19-2018 00:00:00.945 +0000 INFO  LMStackMgr - finished rollover, new lastRolloverTime=1531958400&lt;BR /&gt;
07-19-2018 00:00:28.945 +0000 INFO  LMSlaveInfo - Detected that masterTimeFromSlave(Wed Jul 18 23:59:27 2018) &amp;lt; lastRolloverTime(Thu Jul 19 00:00:00 2018), meaning that the master has already rolled over. Ignore slave persisted usage.&lt;BR /&gt;
07-19-2018 01:59:59.999 +0000 INFO  ExecProcessor - setting reschedule_ms=3600002, for command=python /welldata/splunk/etc/apps/splunk_instrumentation/bin/instrumentation.py&lt;BR /&gt;
07-19-2018 03:00:00.001 +0000 INFO  ExecProcessor - setting reschedule_ms=3599999, for command=python /welldata/splunk/etc/apps/splunk_instrumentation/bin/instrumentation.py&lt;BR /&gt;
07-19-2018 03:01:00.599 +0000 WARN  TelemetryHandler - 1531872000.000000&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452282#M20537</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2020-09-29T20:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452283#M20538</link>
      <description>&lt;P&gt;can you paste the content of your outputs.conf here&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 16:53:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452283#M20538</guid>
      <dc:creator>patilsonali1729</dc:creator>
      <dc:date>2018-07-19T16:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452284#M20539</link>
      <description>&lt;P&gt;[root@psdlepkl4 local]# cat outputs.conf&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = 12.34.342.87:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://12.34.342.87:9997]&lt;/P&gt;

&lt;P&gt;This on server where universal forwarder installed&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 17:02:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452284#M20539</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2018-07-19T17:02:31Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452285#M20540</link>
      <description>&lt;P&gt;Is this your first time starting this splunk forwarder?&lt;BR /&gt;
I've add issues after running accept license where I need to stop the splunk instance and re-start it on versions 7.1 and above.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 17:54:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452285#M20540</guid>
      <dc:creator>auraria1</dc:creator>
      <dc:date>2018-07-19T17:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452286#M20541</link>
      <description>&lt;P&gt;Hi Auraria&lt;/P&gt;

&lt;P&gt;Yes, first time after installating universal splunk forwarder..its 7.1.1 version.&lt;BR /&gt;
splunk on A Linux server where splunk installed, Universal forwarder is on B Linux server, were the logs of Linux B will be seen on Linux A.&lt;BR /&gt;
Do I need to start splunkforwarder also, along with splunk?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452286#M20541</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2018-07-19T18:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452287#M20542</link>
      <description>&lt;P&gt;Both need to be running for logs to be indexed. &lt;/P&gt;

&lt;P&gt;I'd try restarting the forwarder:&lt;/P&gt;

&lt;P&gt;/directory to splunk/splunkforwarder/bin/splunk stop&lt;BR /&gt;
/directory to splunk/splunkforwarder/bin/splunk start&lt;/P&gt;

&lt;P&gt;Then check the splunkd logs, let me know if that fixes the issue.&lt;/P&gt;

&lt;P&gt;Quick tip on  troubleshooting and splunkd logs, rename the log to splunkd1 before starting the splunk forwarder and increase the number everytime so it creates a fresh log and you can compare the two.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:25:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452287#M20542</guid>
      <dc:creator>auraria1</dc:creator>
      <dc:date>2018-07-19T18:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452288#M20543</link>
      <description>&lt;P&gt;Thanks for quick reply...&lt;/P&gt;

&lt;P&gt;Restarted splunk forwarder, getting this error on splunkd.logs&lt;BR /&gt;
Weburl is not coming up. &lt;A href="http://hostanme:8000" target="_blank"&gt;http://hostanme:8000&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;WARN  X509Verify - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts your Splunk instance at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: &lt;BR /&gt;
07-19-2018 18:31:56.698 +0000 INFO  WatchedFile - Will begin reading at offset=508858 for file='/welldata/splunk/var/log/introspection/disk_objects.log'.&lt;BR /&gt;
07-19-2018 18:31:56.702 +0000 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/welldata/splunk/var/log/introspection/http_event_collector_metrics.log'.&lt;BR /&gt;
07-19-2018 18:31:56.750 +0000 ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;/P&gt;

&lt;P&gt;Please advice&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:31:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452288#M20543</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2020-09-29T20:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452289#M20544</link>
      <description>&lt;P&gt;When you created your outputs.conf where did you place the file?&lt;/P&gt;

&lt;P&gt;Should be:&lt;/P&gt;

&lt;P&gt;/directory to splunk/splunkforwarder/etc/system/local/outputs.conf&lt;/P&gt;

&lt;P&gt;Be sure it says outputs.conf and not output.conf.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:45:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452289#M20544</guid>
      <dc:creator>auraria1</dc:creator>
      <dc:date>2018-07-19T18:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452290#M20545</link>
      <description>&lt;P&gt;1.Splunk universal forwarder does not have web UI. &lt;BR /&gt;
2.Where is your outputs.conf file located? Please run ./splunk btool --debug outputs list and paste the response here.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:48:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452290#M20545</guid>
      <dc:creator>patilsonali1729</dc:creator>
      <dc:date>2018-07-19T18:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452291#M20546</link>
      <description>&lt;P&gt;Thanks .&lt;/P&gt;

&lt;P&gt;location : /opt/splunkforwarder/etc/system/local&lt;/P&gt;

&lt;P&gt;yes its outputs.conf&lt;/P&gt;

&lt;P&gt;inside outputs.conf&lt;BR /&gt;&lt;BR /&gt;
root@psdlepkl4 local]# cat outputs.conf&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = 12.34.342.87:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://12.34.342.87:9997&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:52:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452291#M20546</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2018-07-19T18:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452292#M20547</link>
      <description>&lt;P&gt;as @patilsonali1729 please post the btool debug output.&lt;/P&gt;

&lt;P&gt;Under [tcpout:default-autolb-group]&lt;BR /&gt;
add:&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;This shouldn't be an issue however.&lt;/P&gt;

&lt;P&gt;Also add the close bracket ( ] )to&lt;BR /&gt;
so this&lt;BR /&gt;
[tcpout-server://12.34.342.87:9997&lt;/P&gt;

&lt;P&gt;to this&lt;/P&gt;

&lt;P&gt;[tcpout-server://12.34.342.87:9997]&lt;/P&gt;

&lt;P&gt;^This is also not needed as you specified the server and the output in the default autolb group.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 18:57:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452292#M20547</guid>
      <dc:creator>auraria1</dc:creator>
      <dc:date>2018-07-19T18:57:30Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452293#M20548</link>
      <description>&lt;P&gt;Hi Patil,&lt;/P&gt;

&lt;P&gt;Yes, Splunk universal forwarder does not have web UI. I am saying about splunk enterprises this installed on Linux A machine and splunk forwarder on Linux B machine. Splunk B logs need to see forwarder on Linux A(Splunk web url).&lt;/P&gt;

&lt;P&gt;output conf file of universal forwarder is located at : /opt/splunkforwarder/etc/system/local&lt;/P&gt;

&lt;P&gt;after running run ./splunk btool --debug outputs list &lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/etc/system/default/outputs.conf                        [syslog]&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        maxEventSize = 1024&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        priority = &amp;lt;13&amp;gt;&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        type = udp&lt;BR /&gt;
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf [tcpout]&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        ackTimeoutOnShutdown = 30&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        autoLBFrequency = 30&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        autoLBVolume = 0&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        blockOnCloning = true&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        blockWarnThreshold = 100&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        cipherSuite = ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:AES256-GCM-SHA384:AES128-GCM-SHA256:AES128-SHA256:ECDH-ECDSA-AES256-GCM-SHA384:ECDH-ECDSA-AES128-GCM-SHA256:ECDH-ECDSA-AES256-SHA384:ECDH-ECDSA-AES128-SHA256&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        compressed = false&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        connectionTimeout = 20&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/outputs.conf                          defaultGroup = default-autolb-group&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        disabled = false&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        dropClonedEventsOnQueueFull = 5&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        dropEventsOnQueueFull = -1&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        ecdhCurves = prime256v1, secp384r1, secp521r1&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        forceTimebasedAutoLB = false&lt;BR /&gt;
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf forwardedindex.0.whitelist = .*&lt;BR /&gt;
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf forwardedindex.1.blacklist = _.*&lt;BR /&gt;
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf forwardedindex.2.whitelist = (_audit|_introspection|_internal|_telemetry)&lt;BR /&gt;
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf forwardedindex.filter.disable = false&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        heartbeatFrequency = 30&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        indexAndForward = false&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        maxConnectionsPerIndexer = 2&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        maxFailuresPerInterval = 2&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        maxQueueSize = auto&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        readTimeout = 300&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        secsInFailureInterval = 1&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        sendCookedData = true&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        sslQuietShutdown = false&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        sslVersions = tls1.2&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        tcpSendBufSz = 0&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        useACK = false&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/outputs.conf                        writeTimeout = 300&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/outputs.conf                          [tcpout-server://10.46.249.41:9997]&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/outputs.conf                          [tcpout:default-autolb-group]&lt;BR /&gt;
/opt/splunkforwarder/etc/system/local/outputs.conf                          server = 10.22.139.99:9997&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:31:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452293#M20548</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2020-09-29T20:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452294#M20549</link>
      <description>&lt;P&gt;Thanks for response.&lt;BR /&gt;
Also add the close bracket ( ] )to already there may be my mistake&lt;/P&gt;

&lt;P&gt;Do I need to add (disabled=0)?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:16:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452294#M20549</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2018-07-19T19:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452295#M20550</link>
      <description>&lt;P&gt;Also, verify if the user running Splunk has read permission to outputs.conf (the user should have access to all the conf files, in short to /opt/splunkforwarder)&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:20:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452295#M20550</guid>
      <dc:creator>patilsonali1729</dc:creator>
      <dc:date>2018-07-19T19:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452296#M20551</link>
      <description>&lt;P&gt;It doesn't hurt.&lt;/P&gt;

&lt;P&gt;After that try starting the forwarder again and let me know.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:20:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452296#M20551</guid>
      <dc:creator>auraria1</dc:creator>
      <dc:date>2018-07-19T19:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452297#M20552</link>
      <description>&lt;P&gt;Good call, &lt;BR /&gt;
@ahmemohs03 I'd run a chown on the entire directory for the dedicated splunk user,&lt;/P&gt;

&lt;P&gt;chown splunk:splunk -R /opt/splunkforwarder/&lt;/P&gt;

&lt;P&gt;Swap out splunk for the user running splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:22:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452297#M20552</guid>
      <dc:creator>auraria1</dc:creator>
      <dc:date>2018-07-19T19:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452298#M20553</link>
      <description>&lt;P&gt;Do you mean -rw------- 1 root root   140 Jul 17 18:39 outputs.conf?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452298#M20553</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2018-07-19T19:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452299#M20554</link>
      <description>&lt;P&gt;I would just change ownership to all the files and folders as it can cause issues in the future in the splunkforwarder directory.&lt;/P&gt;

&lt;P&gt;Did the bracket and the disabled = 0 fix the issue or is it still persisting?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:33:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452299#M20554</guid>
      <dc:creator>auraria1</dc:creator>
      <dc:date>2018-07-19T19:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452300#M20555</link>
      <description>&lt;P&gt;after bracket and the disabled = 0 fix , I did a splunkforwarder restart, but see the error again.&lt;BR /&gt;
 ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:48:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452300#M20555</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2018-07-19T19:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452301#M20556</link>
      <description>&lt;P&gt;Do I need to restart splunk also on another server?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2018 19:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/ERROR-TcpOutputProc-LightWeightForwarder-UniversalForwarder-not/m-p/452301#M20556</guid>
      <dc:creator>ahmemohs03</dc:creator>
      <dc:date>2018-07-19T19:49:27Z</dc:date>
    </item>
  </channel>
</rss>

