<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to get data into Splunk Cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577054#M101929</link>
    <description>&lt;P&gt;Do you see the forwarder's internal logs in Splunk Cloud?&amp;nbsp; If so, then either no inputs are enabled or Splunk is unable to read the input.&amp;nbsp; Check the logs for details.&lt;/P&gt;&lt;P&gt;If you don't see the forwarder's internal logs in Splunk Cloud then there's a problem connecting.&amp;nbsp; Check the UF's logs locally for details.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 13:21:37 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-12-02T13:21:37Z</dc:date>
    <item>
      <title>Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577047#M101926</link>
      <description>&lt;P&gt;1. I have installed universal forwarder and have a Splunk cloud account.&lt;/P&gt;&lt;P&gt;2. On the laptop in universal forwarder, i downloaded the file and execute the command:&amp;nbsp;&amp;nbsp;/opt/splunkforwarder/bin/splunk install app /tmp/splunkclouduf.spl&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3. I restart the splunk process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No data went in, may I know why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: I am trying to forward the Windows event log which is the same host where i installed the Splunk universal forwarder&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 13:02:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577047#M101926</guid>
      <dc:creator>z080236</dc:creator>
      <dc:date>2021-12-02T13:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577054#M101929</link>
      <description>&lt;P&gt;Do you see the forwarder's internal logs in Splunk Cloud?&amp;nbsp; If so, then either no inputs are enabled or Splunk is unable to read the input.&amp;nbsp; Check the logs for details.&lt;/P&gt;&lt;P&gt;If you don't see the forwarder's internal logs in Splunk Cloud then there's a problem connecting.&amp;nbsp; Check the UF's logs locally for details.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 13:21:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577054#M101929</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-12-02T13:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577065#M101932</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2109/Admin/WindowsGDI#Step_3:_Configure_indexes_on_your_Splunk_Cloud_Platform_instance" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2109/Admin/WindowsGDI#Step_3:_Configure_indexes_on_your_Splunk_Cloud_Platform_instance &lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can't I skip step 4 &amp;amp; 5 and go&amp;nbsp; straight towards install the Splunk universal forwarder?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the splunk forwarder I see,&lt;/P&gt;&lt;P&gt;12-02-2021 22:26:21.612 +0800 INFO TailReader [13912 tailreader0] - Batch input finished reading file='C:\Program Files\SplunkUniversalForwarder\var\spool\splunk\tracker.log'&lt;BR /&gt;12-02-2021 22:26:41.414 +0800 INFO AutoLoadBalancedConnectionStrategy [10792 TcpOutEloop] - Found currently active indexer. Connected to idx=54.83.75.76:9997, reuse=1.&lt;BR /&gt;12-02-2021 22:26:52.019 +0800 INFO TailReader [13912 tailreader0] - Batch input finished reading file='C:\Program Files\SplunkUniversalForwarder\var\spool\splunk\tracker.log'&lt;BR /&gt;12-02-2021 22:27:11.318 +0800 INFO AutoLoadBalancedConnectionStrategy [10792 TcpOutEloop] - Found currently active indexer. Connected to idx=54.83.75.76:9997, reuse=1.&lt;BR /&gt;12-02-2021 22:27:22.282 +0800 INFO TailReader [13912 tailreader0] - Batch input finished reading file='C:\Program Files\SplunkUniversalForwarder\var\spool\splunk\tracker.log'&lt;BR /&gt;12-02-2021 22:27:41.208 +0800 INFO AutoLoadBalancedConnectionStrategy [10792 TcpOutEloop] - Found currently active indexer. Connected to idx=54.83.75.76:9997, reuse=1.&lt;BR /&gt;12-02-2021 22:27:51.500 +0800 INFO TailReader [13912 tailreader0] - Batch input finished reading file='C:\Program Files\SplunkUniversalForwarder\var\spool\splunk\tracker.log'&lt;BR /&gt;12-02-2021 22:28:11.073 +0800 INFO AutoLoadBalancedConnectionStrategy [10792 TcpOutEloop] - Found currently active indexer. Connected to idx=54.83.75.76:9997, reuse=1.&lt;BR /&gt;12-02-2021 22:28:21.782 +0800 INFO TailReader [13912 tailreader0] - Batch input finished reading file='C:\Program Files\SplunkUniversalForwarder\var\spool\splunk\tracker.log'&lt;BR /&gt;12-02-2021 22:28:40.951 +0800 INFO AutoLoadBalancedConnectionStrategy [10792 TcpOutEloop] - Found currently active indexer. Connected to idx=54.83.75.76:9997, reuse=1.&lt;BR /&gt;12-02-2021 22:28:52.022 +0800 INFO TailReader [13912 tailreader0] - Batch input finished reading file='C:\Program Files\SplunkUniversalForwarder\var\spool\splunk\tracker.log'&lt;BR /&gt;12-02-2021 22:29:10.804 +0800 INFO AutoLoadBalancedConnectionStrategy [10792 TcpOutEloop] - Found currently active indexer. Connected to idx=54.83.75.76:9997, reuse=1.&lt;BR /&gt;12-02-2021 22:29:22.164 +0800 INFO TailReader [13912 tailreader0] - Batch input finished reading file='C:\Program Files\SplunkUniversalForwarder\var\spool\splunk\tracker.log'&lt;BR /&gt;12-02-2021 22:29:40.691 +0800 INFO AutoLoadBalancedConnectionStrategy [10792 TcpOutEloop] - Found currently active indexer. Connected to idx=54.83.75.76:9997, reuse=1.&lt;BR /&gt;12-02-2021 22:29:52.369 +0800 INFO TailReader [13912 tailreader0] - Batch input finished reading file='C:\Program Files\SplunkUniversalForwarder\var\spool\splunk\tracker.log'&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 14:30:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577065#M101932</guid>
      <dc:creator>z080236</dc:creator>
      <dc:date>2021-12-02T14:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577067#M101933</link>
      <description>&lt;P&gt;&lt;STRONG&gt;From Splunk cloud:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;To set up the Universal Forwarder:&lt;/STRONG&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Download the Splunk universal forwarder.&lt;P&gt;&lt;A href="http://www.splunk.com/download/universalforwarder" target="_blank" rel="noopener"&gt;Splunk Downloads web page&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Install the universal forwarder on one or more machines in your network.&lt;P&gt;&lt;A href="https://prd-p-gvnkg.splunkcloud.com/en-US/help?location=splunkclouduf.installation.instructions" target="_blank" rel="noopener"&gt;Installation Instructions&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Download your customized universal forwarder credentials package.&lt;P&gt;&lt;A href="https://prd-p-gvnkg.splunkcloud.com/en-US/splunkd/__raw/servicesNS/admin/splunkclouduf/static/splunkclouduf.spl" target="_blank" rel="noopener"&gt;Download Universal Forwarder Credentials&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Install the universal forwarder credentials package on each universal forwarder in your network.&lt;P&gt;&lt;A href="https://prd-p-gvnkg.splunkcloud.com/en-US/help?location=splunkclouduf.installation.instructions" target="_blank" rel="noopener"&gt;Installation Instructions&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;Configure your universal forwarders to send data to the Splunk platform.&lt;P&gt;&lt;A href="https://prd-p-gvnkg.splunkcloud.com/en-US/help?location=splunkclouduf.configuration.instructions" target="_blank" rel="noopener"&gt;Configure data inputs&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Thu, 02 Dec 2021 14:41:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577067#M101933</guid>
      <dc:creator>z080236</dc:creator>
      <dc:date>2021-12-02T14:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577068#M101934</link>
      <description>&lt;P&gt;What you have gotten on step 7? If connection works then there should be some events which has come from your window workstation.&lt;/P&gt;&lt;P&gt;If/when you are skipping step 4&amp;amp;5 then there haven' teen configured any real inputs to your windows infra unless you add those manually on your UF hosts.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 14:40:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577068#M101934</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-02T14:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577076#M101935</link>
      <description>&lt;P&gt;I added inputs.conf in&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\100_prd-p-gvnkg_splunkcloud\local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;renderXml=true&lt;BR /&gt;index=winevent&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[WinEventLog://Security]&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;BR /&gt;evt_resolve_ad_obj = 1&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;renderXml=true&lt;BR /&gt;index=winevent&lt;/P&gt;&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;disabled = 0&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;renderXml=true&lt;BR /&gt;index=winevent&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I saw some application logs inside, but seems like they did not parse correctly. I go ahead and install the Windows add-on app on the Splunk cloud?&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/742/" target="_blank"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 14:59:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577076#M101935</guid>
      <dc:creator>z080236</dc:creator>
      <dc:date>2021-12-02T14:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577081#M101937</link>
      <description>&lt;P&gt;In splunk cloud, I went to Apps -&amp;gt; Browse more apps&lt;/P&gt;&lt;P&gt;Enter windows&lt;/P&gt;&lt;P&gt;Installed Splunk Add-On for Microsoft Windows&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that, the data was parsed correctly, can mark this as solved.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 15:06:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/577081#M101937</guid>
      <dc:creator>z080236</dc:creator>
      <dc:date>2021-12-02T15:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/592781#M103754</link>
      <description>&lt;P&gt;&lt;SPAN&gt;1. I have installed universal forwarder and have a Splunk cloud account.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. Installed Splunk using this command&amp;nbsp;/opt/splunkforwarder/bin/splunk install app /tmp/splunkclouduf.spl.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. restarted to get changes into effect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;no logs in Splunk cloud&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;index= "*" found nothing&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Apr 2022 22:50:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/592781#M103754</guid>
      <dc:creator>bharath-boppid</dc:creator>
      <dc:date>2022-04-06T22:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get data into Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/592792#M103760</link>
      <description>&lt;P&gt;This question already has a solution.&amp;nbsp; Please post a new question with details about your problem.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2022 00:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-data-into-Splunk-Cloud/m-p/592792#M103760</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-04-07T00:16:23Z</dc:date>
    </item>
  </channel>
</rss>

