<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal Forwarder- Am I misunderstanding the UF? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Am-I-misunderstanding-the-UF/m-p/616354#M106491</link>
    <description>&lt;P&gt;Good Morning all ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I have a standalone splunk installation , there is no syslog data being transmitted and Im really not getting any data collected from the universal forwarded it is phoning home however i dont see any data from the linux server that it is installed on. I dont see any log modifications or anything . am i mis understanding the UF&lt;/P&gt;</description>
    <pubDate>Fri, 07 Oct 2022 17:22:18 GMT</pubDate>
    <dc:creator>socks</dc:creator>
    <dc:date>2022-10-07T17:22:18Z</dc:date>
    <item>
      <title>Universal Forwarder- Am I misunderstanding the UF?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Am-I-misunderstanding-the-UF/m-p/616354#M106491</link>
      <description>&lt;P&gt;Good Morning all ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I have a standalone splunk installation , there is no syslog data being transmitted and Im really not getting any data collected from the universal forwarded it is phoning home however i dont see any data from the linux server that it is installed on. I dont see any log modifications or anything . am i mis understanding the UF&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 17:22:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Am-I-misunderstanding-the-UF/m-p/616354#M106491</guid>
      <dc:creator>socks</dc:creator>
      <dc:date>2022-10-07T17:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder .. am i wrong ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Am-I-misunderstanding-the-UF/m-p/616358#M106493</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/242522"&gt;@socks&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me better understand your architecture:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have a stand alone Splunk on a linux server,&lt;/LI&gt;&lt;LI&gt;then you have a Universal Forwarder on another machine (not on the same) connected with the Splunk Server,&lt;/LI&gt;&lt;LI&gt;you don't see any data from the Universal Forwarder in the Splunk Server,&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;is it correct?&lt;/P&gt;&lt;P&gt;have you seen the documentation about getting data in from forwarders at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Usingforwardingagents&lt;/A&gt;&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-configure-a-Splunk-Forwarder-on-Linux/m-p/72078" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-configure-a-Splunk-Forwarder-on-Linux/m-p/72078&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you configured receinving in the Splunk Server [Settings -- Forwarding and Receiving -- Receiving]?&lt;/P&gt;&lt;P&gt;Did you configured your Universal Forwarder to send data to Splunk modifyng outputs.conf ?&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.0.1/Forwarder/Configuretheuniversalforwarder" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.0.1/Forwarder/Configuretheuniversalforwarder&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you configured inputs?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 17:26:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Am-I-misunderstanding-the-UF/m-p/616358#M106493</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-07T17:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder .. am i wrong ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Am-I-misunderstanding-the-UF/m-p/616376#M106500</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;here is instructions how to install UF and enable receiving on indexer (on all in one node).&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/9.0.1/Forwarder/Installanixuniversalforwarder" target="_blank"&gt;https://docs.splunk.com/Documentation/Forwarder/9.0.1/Forwarder/Installanixuniversalforwarder&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Your issue sounds like you haven’t configured any inputs! Have you any serverclasses and apps on your server side? Have you check that you have any internal logs from that node? Just check from MC or just wit SPL&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;your UF&amp;gt; sourcetype=splunkd earliest=0&lt;/LI-CODE&gt;&lt;P&gt;If you found any events then it can send events to &amp;nbsp;server. If not then probably &amp;nbsp;you are missing outputs.conf&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Admin/Outputsconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Admin/Outputsconf&lt;/A&gt;. Just add this to point your server and then internal events should found on server.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2022 20:24:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Am-I-misunderstanding-the-UF/m-p/616376#M106500</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-10-07T20:24:24Z</dc:date>
    </item>
  </channel>
</rss>

