<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder/m-p/57292#M11191</link>
    <description>&lt;P&gt;Hi I am trying to evaluate Splunk to monitor log (simple txt format) from directory. &lt;BR /&gt;
I am able to setup everything in my local Windows Server 2008 R2 machine and I can see my log data.&lt;/P&gt;

&lt;P&gt;Now I want to see log from remote machine [Windows 7], I have installed Splunk forwarder [splunkforwarder-4.3.2-123586-x64-release.msi] and set the required informations all ports are default according to documentation.&lt;/P&gt;

&lt;P&gt;Now question is How to test my forwarder, I have search in KB but its very hard to understand in most of the cases "How To" information is missing.&lt;/P&gt;

&lt;P&gt;I tried according to this thread &lt;A href="http://splunk-base.splunk.com/answers/41307/splunk-forwarder"&gt;http://splunk-base.splunk.com/answers/41307/splunk-forwarder&lt;/A&gt;&lt;BR /&gt;
but no luck.&lt;/P&gt;

&lt;P&gt;[From Splunk Documentation]&lt;BR /&gt;
 1. Test the results to confirm that forwarding, along with any configured behaviors like load balancing or routing, is occurring as expected. &lt;/P&gt;

&lt;P&gt;How to test???&lt;BR /&gt;
How to and where to configure???&lt;/P&gt;

&lt;P&gt;Using Network Monitor I can see forwarder is sending data and my server receiving data.&lt;BR /&gt;
but I can't see in Splunk UI.&lt;/P&gt;

&lt;P&gt;Is there any way how to see the remote data and Host in Splunk UI? How to add multiple forwarder in Splunk?&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;

&lt;P&gt;Manoj &lt;/P&gt;</description>
    <pubDate>Tue, 22 May 2012 15:25:06 GMT</pubDate>
    <dc:creator>jangid</dc:creator>
    <dc:date>2012-05-22T15:25:06Z</dc:date>
    <item>
      <title>Splunk Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder/m-p/57292#M11191</link>
      <description>&lt;P&gt;Hi I am trying to evaluate Splunk to monitor log (simple txt format) from directory. &lt;BR /&gt;
I am able to setup everything in my local Windows Server 2008 R2 machine and I can see my log data.&lt;/P&gt;

&lt;P&gt;Now I want to see log from remote machine [Windows 7], I have installed Splunk forwarder [splunkforwarder-4.3.2-123586-x64-release.msi] and set the required informations all ports are default according to documentation.&lt;/P&gt;

&lt;P&gt;Now question is How to test my forwarder, I have search in KB but its very hard to understand in most of the cases "How To" information is missing.&lt;/P&gt;

&lt;P&gt;I tried according to this thread &lt;A href="http://splunk-base.splunk.com/answers/41307/splunk-forwarder"&gt;http://splunk-base.splunk.com/answers/41307/splunk-forwarder&lt;/A&gt;&lt;BR /&gt;
but no luck.&lt;/P&gt;

&lt;P&gt;[From Splunk Documentation]&lt;BR /&gt;
 1. Test the results to confirm that forwarding, along with any configured behaviors like load balancing or routing, is occurring as expected. &lt;/P&gt;

&lt;P&gt;How to test???&lt;BR /&gt;
How to and where to configure???&lt;/P&gt;

&lt;P&gt;Using Network Monitor I can see forwarder is sending data and my server receiving data.&lt;BR /&gt;
but I can't see in Splunk UI.&lt;/P&gt;

&lt;P&gt;Is there any way how to see the remote data and Host in Splunk UI? How to add multiple forwarder in Splunk?&lt;/P&gt;

&lt;P&gt;Thanks in advance&lt;/P&gt;

&lt;P&gt;Manoj &lt;/P&gt;</description>
      <pubDate>Tue, 22 May 2012 15:25:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder/m-p/57292#M11191</guid>
      <dc:creator>jangid</dc:creator>
      <dc:date>2012-05-22T15:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder/m-p/57293#M11192</link>
      <description>&lt;P&gt;Did you specify during install to monitor anything?  For the windows installer it will ask, but for the *nix installs it doesn't actually monitor anything outside of itself.  I've seen that happen to quite a few new users that come into the #splunk IRC channel.&lt;/P&gt;

&lt;P&gt;To verify what you are monitoring on the forwarder, you can run the following from a command window:  splunk cmd btool inputs list --debug&lt;/P&gt;

&lt;P&gt;This will show you every input, along with what app is implementing it.&lt;/P&gt;

&lt;P&gt;Also, you can search the _internal index for data by adding:  index=_internal  to your search.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:51:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder/m-p/57293#M11192</guid>
      <dc:creator>mikelanghorst</dc:creator>
      <dc:date>2020-09-28T11:51:32Z</dc:date>
    </item>
  </channel>
</rss>

