<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integration Issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675014#M112982</link>
    <description>&lt;P&gt;I want to connect Splunk to the Linux server, and I downloaded the UF on the Linux server to get the security logs from it. After I created the server class and added clients to it, I downloaded the UF to it and made 2 apps (one for nix and one for main) to receive logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I searched the search head, no logs appeared&lt;BR /&gt;I think the error is in the nix app. Does anyone know what modifications are required to be made on the nix app so that I can take the security logs?&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jan 2024 10:36:26 GMT</pubDate>
    <dc:creator>aly347774</dc:creator>
    <dc:date>2024-01-22T10:36:26Z</dc:date>
    <item>
      <title>No events from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/674993#M112977</link>
      <description>&lt;P&gt;I installed Universal Forwarder On Linux Machine and integrate it with Splunk , but their is no logs returned on Splunk Search Head ,&amp;nbsp; as per your Knowledge I`m currently working on distributed Splunk Enterprise .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Recommendations ?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 08:29:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/674993#M112977</guid>
      <dc:creator>aly347774</dc:creator>
      <dc:date>2024-01-22T08:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: Integration Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/674998#M112978</link>
      <description>&lt;P&gt;What do you mean by "I integrated my UF with Splunk"?&lt;/P&gt;&lt;P&gt;Also the usual questions.&lt;/P&gt;&lt;P&gt;1. Do you have _any_ events from this forwarder (especially forwarder's own logs in _internal index) in your Splunk?&lt;/P&gt;&lt;P&gt;2. Do you have connectivity from your UF to your receiving component(s)? Did you verify it manually?&lt;/P&gt;&lt;P&gt;3. Did you check your forwarder's logs ($SPLUNK_HOME/var/log/splunk/splunkd.log) for errors?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 08:28:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/674998#M112978</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-22T08:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: No events from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675013#M112981</link>
      <description>&lt;P&gt;I want to connect Splunk to the Linux server, and I downloaded the UF on the Linux server to get the security logs from it. After I created the server class and added clients to it, I downloaded the UF to it and made 2 apps (one for nix and one for main) to receive logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I searched the search head, no logs appeared&lt;BR /&gt;I think the error is in the nix app. Does anyone know what modifications are required to be made on the nix app so that I can take the security logs?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 10:33:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675013#M112981</guid>
      <dc:creator>aly347774</dc:creator>
      <dc:date>2024-01-22T10:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Integration Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675014#M112982</link>
      <description>&lt;P&gt;I want to connect Splunk to the Linux server, and I downloaded the UF on the Linux server to get the security logs from it. After I created the server class and added clients to it, I downloaded the UF to it and made 2 apps (one for nix and one for main) to receive logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I searched the search head, no logs appeared&lt;BR /&gt;I think the error is in the nix app. Does anyone know what modifications are required to be made on the nix app so that I can take the security logs?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 10:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675014#M112982</guid>
      <dc:creator>aly347774</dc:creator>
      <dc:date>2024-01-22T10:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: No events from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675015#M112983</link>
      <description>&lt;P&gt;OK. You downloaded and installed the UF. I assume you started it as well. But as you are apparently using a Deployment Server, did you configure your UF to connect to that DS?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jan 2024 10:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675015#M112983</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-22T10:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: No events from Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675137#M113003</link>
      <description>&lt;P&gt;I have specified a specific index so that we can send the logs to it, but when I search in the search head, there are no logs found.&lt;BR /&gt;Do I have to specify anything in the Input.conf file?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 06:28:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675137#M113003</guid>
      <dc:creator>aly347774</dc:creator>
      <dc:date>2024-01-23T06:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: Integration Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675213#M113013</link>
      <description>&lt;P&gt;OK. Maybe you misunderstand how Splunk works. You don't "connect splunk to a linux server". You install UF on a server and (and that might be one of the parts you're missing) you're making it send events to Splunk.&lt;/P&gt;&lt;P&gt;So, did you verify any of those things I asked you earlier?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jan 2024 19:05:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/No-events-from-Universal-Forwarder/m-p/675213#M113013</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-23T19:05:48Z</dc:date>
    </item>
  </channel>
</rss>

