<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access is Denied from Splunk Server to Remote Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Access-is-Denied-from-Splunk-Server-to-Remote-Server/m-p/13353#M1189</link>
    <description>&lt;P&gt;This is most likely an issue with insufficient permissions.  It has been addressed by &lt;A href="http://answers.splunk.com/questions/495/while-setting-up-a-windows-eventlog-collection-input-why-do-i-get-an-http-500" rel="nofollow"&gt;this&lt;/A&gt; answers post.&lt;/P&gt;</description>
    <pubDate>Thu, 13 May 2010 04:11:19 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2010-05-13T04:11:19Z</dc:date>
    <item>
      <title>Access is Denied from Splunk Server to Remote Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Access-is-Denied-from-Splunk-Server-to-Remote-Server/m-p/13352#M1188</link>
      <description>&lt;P&gt;I am trying to forward event logs from a Windows XP machine to a Windows 2003 machine.  I set up Splunk on the Windows XP machine to forward to the Windows 2003 machine (receiving). &lt;/P&gt;

&lt;P&gt;I have tried adding data inputs as 'Local Event Log Connection', 'Remote Event Log Collection', and 'WMI Collections'.   However, when I test connections, I receive an error message saying that I get the following error message "Failed to fetch data: In handler 'win-wmi-find-collection': Unable to get wmi classes from host '10.21.45.10': -0x7ff8fffb- Access is denied.  Make sure WMI is configured correctly."&lt;/P&gt;

&lt;P&gt;When I test connection using the wbemtest, I receive an error message saying that "Access is Denied" as well.  There is no Active Directory set up on the machines I am working on.  They are on the same subnet.  I have changed a lot of the settings, permissions, and services around on the machines in past few days and was wondering if anyone knew exactly what settings or permissions needed to be enabled/disabled/started.  Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2010 01:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Access-is-Denied-from-Splunk-Server-to-Remote-Server/m-p/13352#M1188</guid>
      <dc:creator>ericmoss</dc:creator>
      <dc:date>2010-05-13T01:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Access is Denied from Splunk Server to Remote Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Access-is-Denied-from-Splunk-Server-to-Remote-Server/m-p/13353#M1189</link>
      <description>&lt;P&gt;This is most likely an issue with insufficient permissions.  It has been addressed by &lt;A href="http://answers.splunk.com/questions/495/while-setting-up-a-windows-eventlog-collection-input-why-do-i-get-an-http-500" rel="nofollow"&gt;this&lt;/A&gt; answers post.&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2010 04:11:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Access-is-Denied-from-Splunk-Server-to-Remote-Server/m-p/13353#M1189</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-05-13T04:11:19Z</dc:date>
    </item>
  </channel>
</rss>

