<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic First Time Users Configuration Questions Regarding Forwarding in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14194#M1405</link>
    <description>&lt;P&gt;I've found how to get data from a remote users Security Log but we are after a centralised area to keep these logs. I then set the Splunk server to become a receiver and then a test server as a light forwarder. How do I know that it is working? Presumably this data is then stored on the Splunk server somewhere? Is this the best way to get my centralised data?&lt;/P&gt;</description>
    <pubDate>Tue, 25 May 2010 21:08:12 GMT</pubDate>
    <dc:creator>wdc</dc:creator>
    <dc:date>2010-05-25T21:08:12Z</dc:date>
    <item>
      <title>First Time Users Configuration Questions Regarding Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14194#M1405</link>
      <description>&lt;P&gt;I've found how to get data from a remote users Security Log but we are after a centralised area to keep these logs. I then set the Splunk server to become a receiver and then a test server as a light forwarder. How do I know that it is working? Presumably this data is then stored on the Splunk server somewhere? Is this the best way to get my centralised data?&lt;/P&gt;</description>
      <pubDate>Tue, 25 May 2010 21:08:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14194#M1405</guid>
      <dc:creator>wdc</dc:creator>
      <dc:date>2010-05-25T21:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: First Time Users Configuration Questions Regarding Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14195#M1406</link>
      <description>&lt;P&gt;You'll know its working if you can search on your 'receiving' server and see data that came from your 'forwarding' server.  The data should be getting indexed on the receiver, by default it will write to C:\Program Files\Splunk\var\lib\splunk\defaultdb, and in the search summary interface you should see your forwarding server listed on the list of 'Hosts' on the right-hand side.&lt;/P&gt;

&lt;P&gt;Yes, this is the recommended solution for getting your logs into a centralized location.  There are other ways to implement this, but to keep it straightforward to start with, use a Splunk instance configured as a forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2010 00:30:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14195#M1406</guid>
      <dc:creator>Mick</dc:creator>
      <dc:date>2010-05-26T00:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: First Time Users Configuration Questions Regarding Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14196#M1407</link>
      <description>&lt;P&gt;Did you set the light forwarder to monitor anything on the "forwarding machine"? 
Did you set the light forwarder to send data to the indexer on some specific port?
Did you set up the indexer to listen to the above port?&lt;/P&gt;

&lt;P&gt;If so, then just logging in to you indexer should be enough to tell you that you are receiving data..&lt;/P&gt;

&lt;P&gt;Assuming you are on unix, a cool command to tell you if you are listening on the indexer is 
netstat -an | grep 9997 
where 9997 is the specific port where you are telling the indexer to listen.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2010 00:33:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14196#M1407</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-05-26T00:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: First Time Users Configuration Questions Regarding Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14197#M1408</link>
      <description>&lt;P&gt;eek, Mick beat me to it..&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2010 00:34:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/First-Time-Users-Configuration-Questions-Regarding-Forwarding/m-p/14197#M1408</guid>
      <dc:creator>Genti</dc:creator>
      <dc:date>2010-05-26T00:34:11Z</dc:date>
    </item>
  </channel>
</rss>

