<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configured but inactive Splunk-2-Splunk Forwards in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87633#M3201</link>
    <description>&lt;P&gt;Worked for me. ex.:&lt;BR /&gt;
(ubuntu)&lt;BR /&gt;
sudo ufw allow 9997&lt;/P&gt;</description>
    <pubDate>Sat, 02 Mar 2013 21:06:26 GMT</pubDate>
    <dc:creator>colares</dc:creator>
    <dc:date>2013-03-02T21:06:26Z</dc:date>
    <item>
      <title>Configured but inactive Splunk-2-Splunk Forwards</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87630#M3198</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I am trying to install a light forwarder and I am kind of stumped.&lt;/P&gt;

&lt;P&gt;I did the following steps:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sudo /opt/splunk/bin/splunk start
sudo /opt/splunk/bin/splunk enable app SplunkLightForwarder -auth admin
sudo /opt/splunk/bin/splunk restart
./splunk add forward-server   myserver.com:9997 -auth admin
sudo /opt/splunk/bin/splunk restart
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And at the end I get:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Active Splunk-2-Splunk Forwards:
        None
Configured but inactive Splunk-2-Splunk Forwards:
        myserver.com:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Two issues I can think of are that my indexer is 4.1.4 while forwarder is 4.1.5 - is that a problem? Also, how do I check if splunk runs into any firewall issue?&lt;/P&gt;

&lt;P&gt;I know the Indexer is fine, as I have another splunk forwarder working fine.&lt;/P&gt;

&lt;P&gt;Any Ideas how I make the forwarder active? How do I debug this?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2010 05:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87630#M3198</guid>
      <dc:creator>barryv</dc:creator>
      <dc:date>2010-11-11T05:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Configured but inactive Splunk-2-Splunk Forwards</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87631#M3199</link>
      <description>&lt;P&gt;I have solved this to be a firewall issue. Port 9997 was blocked on the forwarder.
Would be nice to have some indication of this from splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2010 22:07:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87631#M3199</guid>
      <dc:creator>barryv</dc:creator>
      <dc:date>2010-11-11T22:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configured but inactive Splunk-2-Splunk Forwards</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87632#M3200</link>
      <description>&lt;P&gt;I experienced this same "Configured but inactive forwards" problem. For me, the firewall was not the issue. Splunk Support confirmed to me that there is a bug in Splunk forwarder 5.0.1. I posted the details of the successful work around solution at&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/70729/"&gt;http://splunk-base.splunk.com/answers/70729/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jan 2013 20:46:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87632#M3200</guid>
      <dc:creator>gregcoats</dc:creator>
      <dc:date>2013-01-10T20:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Configured but inactive Splunk-2-Splunk Forwards</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87633#M3201</link>
      <description>&lt;P&gt;Worked for me. ex.:&lt;BR /&gt;
(ubuntu)&lt;BR /&gt;
sudo ufw allow 9997&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2013 21:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87633#M3201</guid>
      <dc:creator>colares</dc:creator>
      <dc:date>2013-03-02T21:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Configured but inactive Splunk-2-Splunk Forwards</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87634#M3202</link>
      <description>&lt;P&gt;This is happening to me with firewall turned OFF and forwarder version 5.03 in Windows.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2013 23:56:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87634#M3202</guid>
      <dc:creator>ta_viewpointcs</dc:creator>
      <dc:date>2013-06-27T23:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configured but inactive Splunk-2-Splunk Forwards</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87635#M3203</link>
      <description>&lt;P&gt;No firewall, SearchHead, Indexer and UF all three on different Ubuntu Linux (64-bit) boxes.&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2013 05:51:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Configured-but-inactive-Splunk-2-Splunk-Forwards/m-p/87635#M3203</guid>
      <dc:creator>miteshvohra</dc:creator>
      <dc:date>2013-07-14T05:51:47Z</dc:date>
    </item>
  </channel>
</rss>

