<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Setting up Forwarder and Testing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56801#M11065</link>
    <description>&lt;P&gt;Well, you could check the following things;&lt;/P&gt;

&lt;P&gt;Is there even a network connection between the two machines?&lt;BR /&gt;
open up a CMD prompt and type &lt;CODE&gt;netstat -an | find "ESTABLISHED"&lt;/CODE&gt;&lt;BR /&gt;
If there is no connection between the machines you may have a firewall issue&lt;/P&gt;

&lt;P&gt;Check the &lt;CODE&gt;splunkd.log&lt;/CODE&gt; for errors (located in &lt;CODE&gt;/opt/splunk/var/log/splunk&lt;/CODE&gt; on &lt;CODE&gt;*&lt;/CODE&gt;nix, and in &lt;CODE&gt;c:\program files\splunk[universalforwarder]\var\log\splunk&lt;/CODE&gt; on win&lt;CODE&gt;*&lt;/CODE&gt; - unless you've changed install locations). &lt;/P&gt;

&lt;P&gt;Check to see if you have configured monitoring correctly. On the forwarding end, type &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; at the command line. Ensure that you have gotten your (back)slashes in correctly in your monitor stanzas.&lt;/P&gt;

&lt;P&gt;If neither of these things will help you to get this going, please supply the outputs.conf from the forwarder, and the inputs.conf from both machines. Depending on how you configured Splunk, these are most likely located in &lt;CODE&gt;/splunk/etc/apps/search&lt;/CODE&gt;, &lt;CODE&gt;splunk/etc/apps/launcher&lt;/CODE&gt; or &lt;CODE&gt;/splunk/etc/system/local&lt;/CODE&gt;. You should have more than on instance of each file on both machines.&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2012 09:42:33 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2012-01-25T09:42:33Z</dc:date>
    <item>
      <title>Setting up Forwarder and Testing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56800#M11064</link>
      <description>&lt;P&gt;So, I've installed and configured the Splunk forward on my Intranet Server.  I'm trying to get the IIS logs from &lt;CODE&gt;\Windows\Syste32\LogFiles\W3SVC&lt;/CODE&gt; folder.  I think that I've configured it properly and have set up the receiving in Manager.  Is there anything else on the reciever that I need to set up?  I'm not getting any files.  How can I test to see if the Intranet Server is even sending the Data?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2012 18:49:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56800#M11064</guid>
      <dc:creator>bherbert</dc:creator>
      <dc:date>2012-01-24T18:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Forwarder and Testing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56801#M11065</link>
      <description>&lt;P&gt;Well, you could check the following things;&lt;/P&gt;

&lt;P&gt;Is there even a network connection between the two machines?&lt;BR /&gt;
open up a CMD prompt and type &lt;CODE&gt;netstat -an | find "ESTABLISHED"&lt;/CODE&gt;&lt;BR /&gt;
If there is no connection between the machines you may have a firewall issue&lt;/P&gt;

&lt;P&gt;Check the &lt;CODE&gt;splunkd.log&lt;/CODE&gt; for errors (located in &lt;CODE&gt;/opt/splunk/var/log/splunk&lt;/CODE&gt; on &lt;CODE&gt;*&lt;/CODE&gt;nix, and in &lt;CODE&gt;c:\program files\splunk[universalforwarder]\var\log\splunk&lt;/CODE&gt; on win&lt;CODE&gt;*&lt;/CODE&gt; - unless you've changed install locations). &lt;/P&gt;

&lt;P&gt;Check to see if you have configured monitoring correctly. On the forwarding end, type &lt;CODE&gt;splunk list monitor&lt;/CODE&gt; at the command line. Ensure that you have gotten your (back)slashes in correctly in your monitor stanzas.&lt;/P&gt;

&lt;P&gt;If neither of these things will help you to get this going, please supply the outputs.conf from the forwarder, and the inputs.conf from both machines. Depending on how you configured Splunk, these are most likely located in &lt;CODE&gt;/splunk/etc/apps/search&lt;/CODE&gt;, &lt;CODE&gt;splunk/etc/apps/launcher&lt;/CODE&gt; or &lt;CODE&gt;/splunk/etc/system/local&lt;/CODE&gt;. You should have more than on instance of each file on both machines.&lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 09:42:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56801#M11065</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-01-25T09:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Forwarder and Testing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56802#M11066</link>
      <description>&lt;P&gt;01-25-2012 12:24:56.633 -0500 WARN  DeploymentClient - Unable to send handshake message to deployment server. Error status is: not_connected&lt;BR /&gt;
01-25-2012 12:25:04.821 -0500 WARN  TcpOutputProc - Cooked connection to ip=10.0.50.87:9997 timed out&lt;/P&gt;

&lt;P&gt;Looking at the Event Viewer on the Reciever it appears the local firewall is blocking the packets from the forwarder.  I assume I'll need to add an exception to the firewall but, what exactly do I need to add?  Doesn't appear its using the same port everytime. Suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 17:59:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56802#M11066</guid>
      <dc:creator>bherbert</dc:creator>
      <dc:date>2012-01-25T17:59:57Z</dc:date>
    </item>
    <item>
      <title>Re: Setting up Forwarder and Testing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56803#M11067</link>
      <description>&lt;P&gt;Well, I'm not too familiar with configuring &lt;INSERT your="" fw="" here=""&gt;. As for ports, the splunk indexer (receiver) is using the same port all the time, unless you have made an advanced configuration. Most people tend to use port 9997 for log transport. If your indexer is also a Deployment Server, you want to allow traffic from your forwarder to port 8089 (default) on the server.&lt;/INSERT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2012 16:12:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Setting-up-Forwarder-and-Testing/m-p/56803#M11067</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-01-26T16:12:42Z</dc:date>
    </item>
  </channel>
</rss>

