<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Univeral forwarder not forwarding in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61021#M12117</link>
    <description>&lt;P&gt;[EDIT2]&lt;/P&gt;

&lt;P&gt;Domain and dns information seems to be sent to the indexer, but not any logs from the security, application or system event log&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jun 2013 12:50:30 GMT</pubDate>
    <dc:creator>systemsatpayzon</dc:creator>
    <dc:date>2013-06-12T12:50:30Z</dc:date>
    <item>
      <title>Univeral forwarder not forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61018#M12114</link>
      <description>&lt;P&gt;I have a problem with a universal forwarder as i configured on a domain controller to use with splunk app for active directory. The forwarder is not forwarding anything. what i have done so far:&lt;BR /&gt;
 1. installed the forwarder to gather remote data and used an domain admin account. i did not check any of the checkboxes during the installation. but i typed in the reciving indexer when asked for&lt;BR /&gt;
 2. i have downloaded and copied the folders Splunk_TA_windows, TA-DNSServer-NT6 and TA-DomainController-NT6 to the apps directory on the universal forwarder&lt;BR /&gt;
 3. I have put a inputs.conf file under Splunk_TA_windows\local folder and then restarted the forwarder&lt;/P&gt;

&lt;P&gt;But noting is sent to indexer. I am sure that there is no firewall or anything like that blocking because i first installed the forwarder as usual and checked the security log input in the installation wizard (after reading the manual about splunk app for active directory i uninstalled it) and saw that events where sent to and recieved by the indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:04:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61018#M12114</guid>
      <dc:creator>systemsatpayzon</dc:creator>
      <dc:date>2020-09-28T14:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Univeral forwarder not forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61019#M12115</link>
      <description>&lt;P&gt;Have you seen anything in the logs on the universal forwarder?&lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME\var\log\splunk\splunkd.log&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2013 11:34:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61019#M12115</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2013-06-12T11:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Univeral forwarder not forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61020#M12116</link>
      <description>&lt;P&gt;What should i look for? the rows below seems suspicious..&lt;/P&gt;

&lt;P&gt;6-12-2013 12:17:13.440 +0200 ERROR TcpOutputFd - Read error. Either the application has not called WSAStartup, or WSAStartup failed.&lt;BR /&gt;
06-12-2013 12:17:13.440 +0200 INFO  TcpOutputProc - Connection to 192.168.19.47:9997 closed. Read error. Either the application has not called WSAStartup, or WSAStartup failed.&lt;/P&gt;

&lt;P&gt;[EDIT]&lt;BR /&gt;
further down this message is written, so i guess that there are no connection problem&lt;BR /&gt;
INFO  TcpOutputProc - Connected to idx=192.168.19.47:9997&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2013 11:52:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61020#M12116</guid>
      <dc:creator>systemsatpayzon</dc:creator>
      <dc:date>2013-06-12T11:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: Univeral forwarder not forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61021#M12117</link>
      <description>&lt;P&gt;[EDIT2]&lt;/P&gt;

&lt;P&gt;Domain and dns information seems to be sent to the indexer, but not any logs from the security, application or system event log&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2013 12:50:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61021#M12117</guid>
      <dc:creator>systemsatpayzon</dc:creator>
      <dc:date>2013-06-12T12:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Univeral forwarder not forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61022#M12118</link>
      <description>&lt;P&gt;I would double check your inputs.conf file under your Splunk_TA_Windows app.  Personally I always copy the inputs.conf from the default to the local folder then edit the stanzas for the appropriate event viewer containers and add the line index=... where you specify the index you want the logs to go into assuming you are not sending them to the default index.&lt;/P&gt;

&lt;P&gt;You did not mention setting up an outputs.conf to point to your indexer. Though if 192.168.19.47 is your indexer then you probably did that.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:06:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61022#M12118</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2020-09-28T14:06:20Z</dc:date>
    </item>
    <item>
      <title>Re: Univeral forwarder not forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61023#M12119</link>
      <description>&lt;P&gt;thanks for the tips.. here is a snippet from my inputs.conf found in C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_windows\local&lt;/P&gt;

&lt;P&gt;[default]&lt;/P&gt;

&lt;P&gt;evt_dc_name =&lt;/P&gt;

&lt;P&gt;evt_dns_name =&lt;/P&gt;

&lt;H6&gt;OS Logs&lt;/H6&gt;

&lt;P&gt;[WinEventLog:Application]&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;start_from = oldest&lt;/P&gt;

&lt;P&gt;current_only = 0&lt;/P&gt;

&lt;P&gt;checkpointInterval = 5&lt;/P&gt;

&lt;P&gt;[WinEventLog:Security]&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;start_from = oldest&lt;/P&gt;

&lt;P&gt;current_only = 0&lt;/P&gt;

&lt;P&gt;evt_resolve_ad_obj = 1&lt;/P&gt;

&lt;P&gt;checkpointInterval = 5&lt;/P&gt;

&lt;P&gt;[WinEventLog:System]&lt;/P&gt;

&lt;P&gt;disabled = 0&lt;/P&gt;

&lt;P&gt;start_from = oldest&lt;/P&gt;

&lt;P&gt;current_only = 0&lt;/P&gt;

&lt;P&gt;checkpointInterval = 5&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:06:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61023#M12119</guid>
      <dc:creator>systemsatpayzon</dc:creator>
      <dc:date>2020-09-28T14:06:43Z</dc:date>
    </item>
    <item>
      <title>Re: Univeral forwarder not forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61024#M12120</link>
      <description>&lt;P&gt;When i removed the app folder TA-DNSServer-NT6 from splunk and restarted splunk it starts to forward events! the server is a DC with ad integrated DNS.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2013 06:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Univeral-forwarder-not-forwarding/m-p/61024#M12120</guid>
      <dc:creator>systemsatpayzon</dc:creator>
      <dc:date>2013-06-18T06:58:42Z</dc:date>
    </item>
  </channel>
</rss>

