<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows logs are not ingesting into splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/571957#M101249</link>
    <description>&lt;P&gt;Dears,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the deployment server in DMZ zone and indexers are in DRN zone. So windows team is pushing the packages using SCCM to our DMZ deployment servers and we can see those clients in our deployment servers but we are not seeing single logs in our splunk that means data is not indexing into our splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the attached architecture screenshot for your reference .&amp;nbsp;&lt;/P&gt;&lt;P&gt;More details :&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Deployment servers in DMZ zone&lt;/P&gt;&lt;P&gt;2. Indexers are in DRN zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#################&lt;/P&gt;&lt;P&gt;The below one is for Windows DMZ&amp;nbsp; log sources to windows universal forwarder&lt;/P&gt;&lt;P&gt;[root@********local]# cat outputs.conf&lt;BR /&gt;[tcpout]&lt;BR /&gt;defaultGroup = xxxx_idx_win_prod&lt;BR /&gt;indexAndForward = false&lt;/P&gt;&lt;P&gt;[indexAndForward]&lt;BR /&gt;index = false&lt;/P&gt;&lt;P&gt;[tcpout:xxxx_idx_win_prod]&lt;BR /&gt;autoLBVolume = 1048576&lt;BR /&gt;server = xxxxsplkwinfrwdr001.xxxxx.xx.xxxx:9997, xxxxsplkwinfrwdr002.xxxxx.xx.xxxx:9997&lt;BR /&gt;sslPassword = password&lt;BR /&gt;clientCert = $SPLUNK_HOME/etc/auth/server.pem&lt;BR /&gt;autoLBFrequency = 5&lt;BR /&gt;useACK = true&lt;/P&gt;&lt;P&gt;########################################&lt;/P&gt;&lt;P&gt;Deployment server configuration :- This will applicable for PROD DRN indexers - Forwarders to indexers&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/deployment-apps/xx-xxxx_xxxx_idx_prod_outputs/local&lt;/P&gt;&lt;P&gt;cat outputs.conf&lt;BR /&gt;[tcpout]&lt;BR /&gt;defaultGroup = xxxx_idx_prod&lt;BR /&gt;indexAndForward = false&lt;/P&gt;&lt;P&gt;[indexAndForward]&lt;BR /&gt;index = false&lt;/P&gt;&lt;P&gt;[tcpout:xxxx_idx_prod]&lt;BR /&gt;autoLBVolume = 1048576&lt;BR /&gt;server = &amp;lt;all drn indexers ip address mentioned here with 9997 port&amp;gt;&lt;BR /&gt;sslPassword = password&lt;BR /&gt;clientCert = $SPLUNK_HOME/etc/auth/server.pem&lt;BR /&gt;autoLBFrequency = 5&lt;BR /&gt;useACK = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#######################&lt;/P&gt;&lt;P&gt;inputs.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;cat inputs.conf&lt;BR /&gt;[splunktcp-ssl:9997]&lt;BR /&gt;disabled=0&lt;BR /&gt;[SSL]&lt;BR /&gt;sslPassword = password&lt;BR /&gt;clientCert = $SPLUNK_HOME/etc/auth/server.pem&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly advise us on this.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk DMZ Flow (005).jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16544iA894048D557E1C1B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk DMZ Flow (005).jpg" alt="Splunk DMZ Flow (005).jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Oct 2021 07:34:38 GMT</pubDate>
    <dc:creator>kiranpanchavat1</dc:creator>
    <dc:date>2021-10-22T07:34:38Z</dc:date>
    <item>
      <title>Windows logs are not ingesting into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/571957#M101249</link>
      <description>&lt;P&gt;Dears,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the deployment server in DMZ zone and indexers are in DRN zone. So windows team is pushing the packages using SCCM to our DMZ deployment servers and we can see those clients in our deployment servers but we are not seeing single logs in our splunk that means data is not indexing into our splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the attached architecture screenshot for your reference .&amp;nbsp;&lt;/P&gt;&lt;P&gt;More details :&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Deployment servers in DMZ zone&lt;/P&gt;&lt;P&gt;2. Indexers are in DRN zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#################&lt;/P&gt;&lt;P&gt;The below one is for Windows DMZ&amp;nbsp; log sources to windows universal forwarder&lt;/P&gt;&lt;P&gt;[root@********local]# cat outputs.conf&lt;BR /&gt;[tcpout]&lt;BR /&gt;defaultGroup = xxxx_idx_win_prod&lt;BR /&gt;indexAndForward = false&lt;/P&gt;&lt;P&gt;[indexAndForward]&lt;BR /&gt;index = false&lt;/P&gt;&lt;P&gt;[tcpout:xxxx_idx_win_prod]&lt;BR /&gt;autoLBVolume = 1048576&lt;BR /&gt;server = xxxxsplkwinfrwdr001.xxxxx.xx.xxxx:9997, xxxxsplkwinfrwdr002.xxxxx.xx.xxxx:9997&lt;BR /&gt;sslPassword = password&lt;BR /&gt;clientCert = $SPLUNK_HOME/etc/auth/server.pem&lt;BR /&gt;autoLBFrequency = 5&lt;BR /&gt;useACK = true&lt;/P&gt;&lt;P&gt;########################################&lt;/P&gt;&lt;P&gt;Deployment server configuration :- This will applicable for PROD DRN indexers - Forwarders to indexers&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/deployment-apps/xx-xxxx_xxxx_idx_prod_outputs/local&lt;/P&gt;&lt;P&gt;cat outputs.conf&lt;BR /&gt;[tcpout]&lt;BR /&gt;defaultGroup = xxxx_idx_prod&lt;BR /&gt;indexAndForward = false&lt;/P&gt;&lt;P&gt;[indexAndForward]&lt;BR /&gt;index = false&lt;/P&gt;&lt;P&gt;[tcpout:xxxx_idx_prod]&lt;BR /&gt;autoLBVolume = 1048576&lt;BR /&gt;server = &amp;lt;all drn indexers ip address mentioned here with 9997 port&amp;gt;&lt;BR /&gt;sslPassword = password&lt;BR /&gt;clientCert = $SPLUNK_HOME/etc/auth/server.pem&lt;BR /&gt;autoLBFrequency = 5&lt;BR /&gt;useACK = true&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#######################&lt;/P&gt;&lt;P&gt;inputs.conf&amp;nbsp;&lt;/P&gt;&lt;P&gt;cat inputs.conf&lt;BR /&gt;[splunktcp-ssl:9997]&lt;BR /&gt;disabled=0&lt;BR /&gt;[SSL]&lt;BR /&gt;sslPassword = password&lt;BR /&gt;clientCert = $SPLUNK_HOME/etc/auth/server.pem&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly advise us on this.&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Splunk DMZ Flow (005).jpg" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16544iA894048D557E1C1B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Splunk DMZ Flow (005).jpg" alt="Splunk DMZ Flow (005).jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 07:34:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/571957#M101249</guid>
      <dc:creator>kiranpanchavat1</dc:creator>
      <dc:date>2021-10-22T07:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: Windows logs are not ingesting into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/571966#M101250</link>
      <description>&lt;P&gt;There are some typical steps you can troubleshoot in such situation:&lt;/P&gt;&lt;P&gt;1) Check what is the final configuration of your forwarders with btool&lt;/P&gt;&lt;P&gt;2) Check whether you do have network connectivity (if you use mutual authentication, which is a good thing, you should do it with a tool that supports TLS auth and check if you can authenticate with your crypto material)&lt;/P&gt;&lt;P&gt;3) Check the logs on both sides for any connection-related errors&lt;/P&gt;&lt;P&gt;4) Dump the network traffic and see how the connection tries go&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 08:21:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/571966#M101250</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-22T08:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: Windows logs are not ingesting into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/572191#M101272</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We can see the below errors in deployment servers&lt;/P&gt;&lt;P&gt;10-14-2021 12:22:42.659 +0300 WARN HttpListener - Socket error from 173.1.194.87:57778 while idling: Read Timeout&lt;BR /&gt;10-14-2021 12:30:39.833 +0300 WARN HttpListener - Socket error from 173.1.196.88:53694 while idling: Read Timeout&lt;BR /&gt;10-14-2021 15:43:05.850 +0300 WARN HttpListener - Socket error from 173.1.194.88:57415 while idling: Read Timeout&lt;BR /&gt;10-14-2021 15:48:27.204 +0300 WARN HttpListener - Socket error from 173.1.194.76:63420 while idling: Read Timeout&lt;BR /&gt;10-14-2021 15:57:15.789 +0300 WARN HttpListener - Socket error from 173.1.194.58:58735 while idling: Read Timeout&lt;BR /&gt;10-14-2021 16:07:40.478 +0300 WARN HttpListener - Socket error from 173.1.194.59:59241 while idling: Read Timeout&lt;BR /&gt;10-14-2021 16:15:52.728 +0300 WARN HttpListener - Socket error from 173.1.194.60:56266 while idling: Read Timeout&lt;BR /&gt;10-14-2021 16:42:01.798 +0300 WARN HttpListener - Socket error from 173.1.194.61:50263 while idling: Read Timeout&lt;BR /&gt;10-14-2021 16:52:24.384 +0300 WARN HttpListener - Socket error from 173.1.194.62:54696 while idling: Read Timeout&lt;BR /&gt;10-14-2021 17:04:25.910 +0300 WARN HttpListener - Socket error from 173.1.196.89:64325 while idling: Read Timeout&lt;BR /&gt;10-14-2021 17:11:19.243 +0300 WARN HttpListener - Socket error from 173.1.214.14:58889 while idling: Read Timeout&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 06:12:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/572191#M101272</guid>
      <dc:creator>kiranpanchavat1</dc:creator>
      <dc:date>2021-10-25T06:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Windows logs are not ingesting into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/572200#M101274</link>
      <description>&lt;P&gt;This on its own should not mean anything serious. Just that some unused connections are getting timed-out. It probably means that there is some misconfiguration on network level because open connections should get properly closed if not used but it's not a big deal.&lt;/P&gt;&lt;P&gt;And deployment server on its own has nothing to do with sending logs from forwarders to indexers.&lt;/P&gt;&lt;P&gt;So check other points.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 07:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-logs-are-not-ingesting-into-splunk/m-p/572200#M101274</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-10-25T07:58:22Z</dc:date>
    </item>
  </channel>
</rss>

