<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Connection error from Windows Heavy Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Connection-error-from-Windows-Heavy-Forwarder/m-p/62238#M12433</link>
    <description>&lt;P&gt;I am trying to forward *.log files from a windows server to a linux index server. I get the WMI data to index; I get the correct files listed from "splunk list monitor", but I don't get the log files indexing from the output of "splunk list monitor" in question.&lt;/P&gt;

&lt;P&gt;I have confirmed the windows server can connect to the index server:&lt;/P&gt;

&lt;P&gt;# netstat -an | grep 9000
tcp        0      0 0.0.0.0:9000            0.0.0.0:*               LISTEN&lt;BR /&gt;
.
. 
&lt;STRONG&gt;tcp        0      0 xx.xx.17.53:9000       xx.xx.16.83:36092      ESTABLISHED&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;And here is the output from the splunkd.log file:&lt;/P&gt;

&lt;P&gt;10-01-2010 07:08:30.975 INFO  TcpInputProc - Connection in cooked mode from xxx-xxx.com
10-01-2010 07:08:30.984 INFO  TcpInputProc - Connection accepted from xxx-xxx.com
10-01-2010 07:08:45.257 WARN  DateParserVerbose - Failed to parse timestamp for event.  Context="source::WinEventLog:Application|host::xxxxxx|WinEventLog:Application|remoteport::33982" Text="quiresLogon/
10-01-2010 07:08:45.257 WARN  DateParserVerbose - Failed to parse timestamp for event.  Context="source::WinEventLog:Application|host::xxx xxx|WinEventLog:Application|remoteport::33982" Text="com;blah.blah.com
&lt;STRONG&gt;10-01-2010 07:21:47.493 ERROR TcpInputProc - Error encountered for connection from host=xxx-xxx.com, ip=10.204.16.83. Timeout
10-01-2010 07:21:47.493 INFO  TcpInputProc - Hostname=xxx-xxx.com closed connection&lt;/STRONG&gt;
10-01-2010 08:01:40.402 INFO  TcpInputProc - Connection in cooked mode from xxx-xxx.com
10-01-2010 08:01:40.413 INFO  TcpInputProc - Connection accepted from xxx-xxx.com&lt;/P&gt;

&lt;P&gt;Any idea why I get WMI and not *.log even though "splunk list monitor" shows I should?&lt;/P&gt;

&lt;P&gt;Pstein&lt;/P&gt;</description>
    <pubDate>Fri, 01 Oct 2010 22:13:33 GMT</pubDate>
    <dc:creator>MasterOogway</dc:creator>
    <dc:date>2010-10-01T22:13:33Z</dc:date>
    <item>
      <title>Connection error from Windows Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Connection-error-from-Windows-Heavy-Forwarder/m-p/62238#M12433</link>
      <description>&lt;P&gt;I am trying to forward *.log files from a windows server to a linux index server. I get the WMI data to index; I get the correct files listed from "splunk list monitor", but I don't get the log files indexing from the output of "splunk list monitor" in question.&lt;/P&gt;

&lt;P&gt;I have confirmed the windows server can connect to the index server:&lt;/P&gt;

&lt;P&gt;# netstat -an | grep 9000
tcp        0      0 0.0.0.0:9000            0.0.0.0:*               LISTEN&lt;BR /&gt;
.
. 
&lt;STRONG&gt;tcp        0      0 xx.xx.17.53:9000       xx.xx.16.83:36092      ESTABLISHED&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;And here is the output from the splunkd.log file:&lt;/P&gt;

&lt;P&gt;10-01-2010 07:08:30.975 INFO  TcpInputProc - Connection in cooked mode from xxx-xxx.com
10-01-2010 07:08:30.984 INFO  TcpInputProc - Connection accepted from xxx-xxx.com
10-01-2010 07:08:45.257 WARN  DateParserVerbose - Failed to parse timestamp for event.  Context="source::WinEventLog:Application|host::xxxxxx|WinEventLog:Application|remoteport::33982" Text="quiresLogon/
10-01-2010 07:08:45.257 WARN  DateParserVerbose - Failed to parse timestamp for event.  Context="source::WinEventLog:Application|host::xxx xxx|WinEventLog:Application|remoteport::33982" Text="com;blah.blah.com
&lt;STRONG&gt;10-01-2010 07:21:47.493 ERROR TcpInputProc - Error encountered for connection from host=xxx-xxx.com, ip=10.204.16.83. Timeout
10-01-2010 07:21:47.493 INFO  TcpInputProc - Hostname=xxx-xxx.com closed connection&lt;/STRONG&gt;
10-01-2010 08:01:40.402 INFO  TcpInputProc - Connection in cooked mode from xxx-xxx.com
10-01-2010 08:01:40.413 INFO  TcpInputProc - Connection accepted from xxx-xxx.com&lt;/P&gt;

&lt;P&gt;Any idea why I get WMI and not *.log even though "splunk list monitor" shows I should?&lt;/P&gt;

&lt;P&gt;Pstein&lt;/P&gt;</description>
      <pubDate>Fri, 01 Oct 2010 22:13:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Connection-error-from-Windows-Heavy-Forwarder/m-p/62238#M12433</guid>
      <dc:creator>MasterOogway</dc:creator>
      <dc:date>2010-10-01T22:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: Connection error from Windows Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Connection-error-from-Windows-Heavy-Forwarder/m-p/62239#M12434</link>
      <description>&lt;P&gt;check if you have windows app enable on your linux indexer first.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Nov 2010 15:51:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Connection-error-from-Windows-Heavy-Forwarder/m-p/62239#M12434</guid>
      <dc:creator>axlbonn</dc:creator>
      <dc:date>2010-11-26T15:51:48Z</dc:date>
    </item>
  </channel>
</rss>

