<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder from Linux to Windows Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72319#M14751</link>
    <description>&lt;P&gt;Note that there is a difference between a raw TCP input and a TCP port for receiving forwarded data from another Splunk instance. In inputs.conf terms, you want a splunktcp input, not a tcp input.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Mar 2013 20:53:19 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-03-22T20:53:19Z</dc:date>
    <item>
      <title>Universal Forwarder from Linux to Windows Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72316#M14748</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I am trying to set up a Universal Forwarder on a Linux box to send Security info to a Windows Server hosting Splunk.&lt;BR /&gt;
I used the below command on the linux box after installing the univiersal forwarder:&lt;BR /&gt;
./splunk add monitor /var/log/ - sourcetype syslog&lt;BR /&gt;
But on the Windows Server,&lt;BR /&gt;
All I see is messages like “x00\x5\x00\x4\xFF\x2\x1\x00”&lt;BR /&gt;
I would like to see something more readable and preferable related to the security log.&lt;BR /&gt;
Any suggestions?&lt;BR /&gt;
Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 18:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72316#M14748</guid>
      <dc:creator>4Msplunk</dc:creator>
      <dc:date>2013-03-22T18:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder from Linux to Windows Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72317#M14749</link>
      <description>&lt;P&gt;Make sure your indexer is set to receive forwarded data on that port, and is not set to receive data as a TCP/UDP input.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 18:36:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72317#M14749</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-03-22T18:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder from Linux to Windows Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72318#M14750</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
Thank you for the reply, but I am set to receive data on a TCP port. &lt;/P&gt;

&lt;P&gt;I had a similar problem with the Windows machines that I installed Universal Forwarder, but a commenter's reply to another post suggested changing the outputs.conf file's sendCookedData value from true to false, and like magic I could read the messages.  But, it did not work on the Linux Universal Forwarder machine's outputs.conf file. I still got messages like \x00\x5\x00\x4\xFF\x2\x1\x00&lt;BR /&gt;
Any Suggestions?&lt;BR /&gt;
Thanks,&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 19:12:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72318#M14750</guid>
      <dc:creator>4Msplunk</dc:creator>
      <dc:date>2013-03-22T19:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder from Linux to Windows Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72319#M14751</link>
      <description>&lt;P&gt;Note that there is a difference between a raw TCP input and a TCP port for receiving forwarded data from another Splunk instance. In inputs.conf terms, you want a splunktcp input, not a tcp input.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 20:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72319#M14751</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-03-22T20:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder from Linux to Windows Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72320#M14752</link>
      <description>&lt;P&gt;Or, in webinterface terms, Manager -&amp;gt; Forwarding and Receiving -&amp;gt; Configure receiving.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2013 21:25:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-from-Linux-to-Windows-Server/m-p/72320#M14752</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2013-03-22T21:25:53Z</dc:date>
    </item>
  </channel>
</rss>

