<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to forward data to Splunk Cloud Instance in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574693#M25035</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I have a local server on my network and would like to send data from this local host to the cloud instance. I have followed the instructions here,&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.2.3/Forwarder/ConfigSCUFCredentials" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.2.3/Forwarder/ConfigSCUFCredentials&lt;/A&gt;&amp;nbsp;and installed the&amp;nbsp;&lt;SPAN&gt;splunkclouduf.spl obtained from my cloud instance profile. However I seem to be getting the following errors:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;11-12-2021 13:56:53.874 +0800 WARN X509Verify [30879 HTTPDispatch] - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts your Splunk instance at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: &amp;lt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates&lt;/A&gt;&amp;gt;&lt;BR /&gt;11-12-2021 13:56:53.901 +0800 INFO UiHttpListener [30942 WebuiStartup] - Web UI disabled in web.conf [settings]; not starting&lt;BR /&gt;11-12-2021 13:56:54.039 +0800 INFO TcpOutputProc [30923 parsing] - _isHttpOutConfigured=NOT_CONFIGURED&lt;BR /&gt;11-12-2021 13:56:54.040 +0800 ERROR TcpOutputProc [30923 parsing] - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;BR /&gt;11-12-2021 13:56:58.961 +0800 WARN TailReader [30932 tailreader0] - Could not send data to output queue (parsingQueue), retrying...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought that once we deploy via the&amp;nbsp;&lt;SPAN&gt;splunkclouduf.spl, we need not configure any outputs.conf file?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any assistance is greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Nov 2021 06:42:47 GMT</pubDate>
    <dc:creator>sairam109</dc:creator>
    <dc:date>2021-11-12T06:42:47Z</dc:date>
    <item>
      <title>Unable to forward data to Splunk Cloud Instance</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574693#M25035</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;I have a local server on my network and would like to send data from this local host to the cloud instance. I have followed the instructions here,&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/8.2.3/Forwarder/ConfigSCUFCredentials" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/8.2.3/Forwarder/ConfigSCUFCredentials&lt;/A&gt;&amp;nbsp;and installed the&amp;nbsp;&lt;SPAN&gt;splunkclouduf.spl obtained from my cloud instance profile. However I seem to be getting the following errors:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;11-12-2021 13:56:53.874 +0800 WARN X509Verify [30879 HTTPDispatch] - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts your Splunk instance at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: &amp;lt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates&lt;/A&gt;&amp;gt;&lt;BR /&gt;11-12-2021 13:56:53.901 +0800 INFO UiHttpListener [30942 WebuiStartup] - Web UI disabled in web.conf [settings]; not starting&lt;BR /&gt;11-12-2021 13:56:54.039 +0800 INFO TcpOutputProc [30923 parsing] - _isHttpOutConfigured=NOT_CONFIGURED&lt;BR /&gt;11-12-2021 13:56:54.040 +0800 ERROR TcpOutputProc [30923 parsing] - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;BR /&gt;11-12-2021 13:56:58.961 +0800 WARN TailReader [30932 tailreader0] - Could not send data to output queue (parsingQueue), retrying...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought that once we deploy via the&amp;nbsp;&lt;SPAN&gt;splunkclouduf.spl, we need not configure any outputs.conf file?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any assistance is greatly appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 06:42:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574693#M25035</guid>
      <dc:creator>sairam109</dc:creator>
      <dc:date>2021-11-12T06:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to forward data to Splunk Cloud Instance</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574709#M25037</link>
      <description>Hi&lt;BR /&gt;You are running UF as a splunk user and also that splunkclouduf.spl are installed and owner by this user?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Fri, 12 Nov 2021 08:19:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574709#M25037</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-12T08:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to forward data to Splunk Cloud Instance</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574718#M25038</link>
      <description>&lt;P&gt;Hi Ismo,&lt;/P&gt;&lt;P&gt;Nice to e-meet you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Thanks for responding to my query.&lt;/P&gt;&lt;P&gt;It appears I might have somehow messed up the installation using the spl credential file. I just did a reinstall and seems to be working fine now. Thanks! Apologies for the inconvenience!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 09:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574718#M25038</guid>
      <dc:creator>sairam109</dc:creator>
      <dc:date>2021-11-12T09:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to forward data to Splunk Cloud Instance</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574747#M25040</link>
      <description>Nice to hear that it works for you. Happy splunking</description>
      <pubDate>Fri, 12 Nov 2021 14:42:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Unable-to-forward-data-to-Splunk-Cloud-Instance/m-p/574747#M25040</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-11-12T14:42:03Z</dc:date>
    </item>
  </channel>
</rss>

