<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal forwarder to Deployment Server Fail in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-to-Deployment-Server-Fail/m-p/76011#M15522</link>
    <description>&lt;P&gt;Heads up, I am only a part time user of splunk at best. &lt;/P&gt;

&lt;P&gt;I have a box which I installed the Universalforwarder and would like it to check into the deployment server. &lt;/P&gt;

&lt;P&gt;1) I believe the deploymentclient.config to be correct as it's identical to others in use (MD5 verified) &lt;BR /&gt;
2) I verified ports are open via telnet hostname.domain.local 8089&lt;/P&gt;

&lt;P&gt;Yet when I goto the deployment server and check the Deployment Monitor Dashboard I don't see it checking in. I waited over an hour and the box does not seem to be under any sort of high load. &lt;/P&gt;

&lt;P&gt;I went to the command line and issues ./splunk list deploy-clients and returned all my other hosts. But not the one in question. &lt;/P&gt;

&lt;P&gt;I opted to tail the log and restart (sudo tail -100f /opt/splunkforwarder/var/log/splunk/splunkd.log) &lt;/P&gt;

&lt;P&gt;I see the below and the logs just sort of end. &lt;BR /&gt;
[code][i]&lt;BR /&gt;
01-02-2013 20:11:41.982 +0000 INFO  TailingProcessor - TailWatcher initializing...&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: batch://$SPLUNK_HOME/var/spool/splunk.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: batch://$SPLUNK_HOME/var/spool/splunk/...stash_new.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/etc/splunk.version.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk/splunkd.log.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  BatchReader - State transitioning from 2 to 0 (initOrResume).&lt;BR /&gt;
01-02-2013 20:11:41.984 +0000 ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;BR /&gt;
01-02-2013 20:11:46.998 +0000 INFO  TailingProcessor - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
[/code][/i]&lt;/P&gt;

&lt;P&gt;Any ideas on steps I would take from here? &lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:02:18 GMT</pubDate>
    <dc:creator>daniel333</dc:creator>
    <dc:date>2020-09-28T13:02:18Z</dc:date>
    <item>
      <title>Universal forwarder to Deployment Server Fail</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-to-Deployment-Server-Fail/m-p/76011#M15522</link>
      <description>&lt;P&gt;Heads up, I am only a part time user of splunk at best. &lt;/P&gt;

&lt;P&gt;I have a box which I installed the Universalforwarder and would like it to check into the deployment server. &lt;/P&gt;

&lt;P&gt;1) I believe the deploymentclient.config to be correct as it's identical to others in use (MD5 verified) &lt;BR /&gt;
2) I verified ports are open via telnet hostname.domain.local 8089&lt;/P&gt;

&lt;P&gt;Yet when I goto the deployment server and check the Deployment Monitor Dashboard I don't see it checking in. I waited over an hour and the box does not seem to be under any sort of high load. &lt;/P&gt;

&lt;P&gt;I went to the command line and issues ./splunk list deploy-clients and returned all my other hosts. But not the one in question. &lt;/P&gt;

&lt;P&gt;I opted to tail the log and restart (sudo tail -100f /opt/splunkforwarder/var/log/splunk/splunkd.log) &lt;/P&gt;

&lt;P&gt;I see the below and the logs just sort of end. &lt;BR /&gt;
[code][i]&lt;BR /&gt;
01-02-2013 20:11:41.982 +0000 INFO  TailingProcessor - TailWatcher initializing...&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: batch://$SPLUNK_HOME/var/spool/splunk.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: batch://$SPLUNK_HOME/var/spool/splunk/...stash_new.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/etc/splunk.version.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk/splunkd.log.&lt;BR /&gt;
01-02-2013 20:11:41.983 +0000 INFO  BatchReader - State transitioning from 2 to 0 (initOrResume).&lt;BR /&gt;
01-02-2013 20:11:41.984 +0000 ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;BR /&gt;
01-02-2013 20:11:46.998 +0000 INFO  TailingProcessor - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;
[/code][/i]&lt;/P&gt;

&lt;P&gt;Any ideas on steps I would take from here? &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:02:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-to-Deployment-Server-Fail/m-p/76011#M15522</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2020-09-28T13:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder to Deployment Server Fail</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-to-Deployment-Server-Fail/m-p/76012#M15523</link>
      <description>&lt;P&gt;Are you getting any data at all from that host ?&lt;/P&gt;

&lt;P&gt;This definately doesn't look right :&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;01-02-2013 20:11:41.984 +0000 ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I would suggest comparing &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/outputs.conf&lt;/CODE&gt; against a working system to see if your universal forwarder knows where to talk to.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2013 13:44:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-to-Deployment-Server-Fail/m-p/76012#M15523</guid>
      <dc:creator>jonuwz</dc:creator>
      <dc:date>2013-01-03T13:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder to Deployment Server Fail</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-to-Deployment-Server-Fail/m-p/76013#M15524</link>
      <description>&lt;P&gt;the second last message just means that there is no valid configuration on the forwarder for where to send the logs (usually on port 9997). That is done in outputs.conf. &lt;/P&gt;

&lt;P&gt;None of the messages above concern the traffic between the forwarder and the deployment server (default port 8089)&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jan 2013 15:04:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-to-Deployment-Server-Fail/m-p/76013#M15524</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-01-03T15:04:45Z</dc:date>
    </item>
  </channel>
</rss>

