<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic My Universal Splunk Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756572#M119992</link>
    <description>&lt;P&gt;Hello Everyone,&amp;nbsp; please for the past four weeks I have been struggling with ensuring that the Universal splunk Forwarder which I installed in my windows 10 virtual machine with sysmon to send logs to my Splunk Enterprise, which is also installed in my host machine (laptop) has been giving me various wrong output, despite the fact that I have configured both the input.conf and output.conf I have also made sure my windows 10 virtual machine can ping my splunk enterprise machine and I also used the command netstat anob find str9997 and it showed me listening I also ensure my firewall is not blocking any port I also enabled the default port 9997 receiving in my splunk enterprise despite all these it is still showing me Active forwards none Configured but inactive forwards 192.168.56.1.9997. I also want to ask a question because my windows 10 virtual machine is set to host only network could that be an obstruction and initially when I configured it, it was fine but now it is giving me such wrong response could it be the authentication. I&amp;nbsp; also wanted to ask should I use the password of my splunk enterprise when I am asked for an authentication usernane and password in my splunk forwarder&lt;/P&gt;</description>
    <pubDate>Tue, 16 Dec 2025 23:56:49 GMT</pubDate>
    <dc:creator>CHIBUIKEM</dc:creator>
    <dc:date>2025-12-16T23:56:49Z</dc:date>
    <item>
      <title>My Universal Splunk Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756572#M119992</link>
      <description>&lt;P&gt;Hello Everyone,&amp;nbsp; please for the past four weeks I have been struggling with ensuring that the Universal splunk Forwarder which I installed in my windows 10 virtual machine with sysmon to send logs to my Splunk Enterprise, which is also installed in my host machine (laptop) has been giving me various wrong output, despite the fact that I have configured both the input.conf and output.conf I have also made sure my windows 10 virtual machine can ping my splunk enterprise machine and I also used the command netstat anob find str9997 and it showed me listening I also ensure my firewall is not blocking any port I also enabled the default port 9997 receiving in my splunk enterprise despite all these it is still showing me Active forwards none Configured but inactive forwards 192.168.56.1.9997. I also want to ask a question because my windows 10 virtual machine is set to host only network could that be an obstruction and initially when I configured it, it was fine but now it is giving me such wrong response could it be the authentication. I&amp;nbsp; also wanted to ask should I use the password of my splunk enterprise when I am asked for an authentication usernane and password in my splunk forwarder&lt;/P&gt;</description>
      <pubDate>Tue, 16 Dec 2025 23:56:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756572#M119992</guid>
      <dc:creator>CHIBUIKEM</dc:creator>
      <dc:date>2025-12-16T23:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: My Universal Splunk Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756574#M119993</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/314762"&gt;@CHIBUIKEM&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Should I use my Splunk Enterprise password? No, you should not use your Splunk Enterprise password.&lt;/SPAN&gt;&lt;BR /&gt;Also what's the wrong output/response you are mentioning here. Can you share the errors you are getting.&lt;/P&gt;&lt;P&gt;Try below and see how it goes,&lt;/P&gt;&lt;P&gt;Check the Forwarder's internal Logs and check for the errors.&lt;BR /&gt;telnet your splunk enterprise port 9997 from your vm&lt;BR /&gt;change your VM's network adapter to "Bridged" mode and test&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 04:12:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756574#M119993</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-12-17T04:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: My Universal Splunk Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756640#M120005</link>
      <description>&lt;P&gt;Thanks Thomas, for your response However I have changed the network to bridged but its still giving me that same wrong response this is the response I get tcp_conn_open_afux&amp;nbsp; ossocket_connect failed with winsock error #10061 ( it says it three times ) then it says Active forwards none, configured but inactive forwards 10.71.224.254:9997 I also attached the picture&amp;nbsp; image of my vm for a clearer view in the first post.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 23:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756640#M120005</guid>
      <dc:creator>CHIBUIKEM</dc:creator>
      <dc:date>2025-12-18T23:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: My Universal Splunk Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756643#M120006</link>
      <description>&lt;P&gt;It looks like Connection refused from your destination(192.168.56.1). Can you confirm 9997 is listening on 192.168.56.1.&lt;BR /&gt;Also run a telnet to this and confirm the connection status.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 03:53:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/My-Universal-Splunk-Forwarder/m-p/756643#M120006</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-12-19T03:53:53Z</dc:date>
    </item>
  </channel>
</rss>

