<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: no forwarder in splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/no-forwarder-in-splunk/m-p/78450#M16055</link>
    <description>&lt;P&gt;i reinstallled splunk and forwarder ,a nd it is working now...&lt;BR /&gt;
seems there was an issue with splunk server configs!!!!!  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Apr 2013 10:19:24 GMT</pubDate>
    <dc:creator>shivanshuk</dc:creator>
    <dc:date>2013-04-09T10:19:24Z</dc:date>
    <item>
      <title>no forwarder in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/no-forwarder-in-splunk/m-p/78449#M16054</link>
      <description>&lt;P&gt;I have installed splunk on machine 1 and universal forwarder on machine 2. I can see on forwarder:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\bin&amp;gt;splunk list forward-server&lt;/CODE&gt;&lt;BR /&gt;
Active forwards:&lt;BR /&gt;
        XXX.XX.XX.XXX:9997&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;
        None&lt;/P&gt;

&lt;P&gt;however when i go and check in splunk, i don't see any forwarder details.&lt;BR /&gt;
the  &lt;CODE&gt;C:\Program Files\Splunk\etc\system\local\inputs.conf&lt;/CODE&gt; is like below.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[default]&lt;BR /&gt;
host = &amp;lt;IP of machine where splunk is installed&amp;gt;&lt;BR /&gt;
[splunktcp://:9997]&lt;BR /&gt;
disabled = 0&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The outputs.conf on forwarder is like below&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;BR /&gt;
[tcpout:default-autolb-group]&lt;BR /&gt;
server = &amp;lt;receiverIP&amp;gt;:9997&lt;BR /&gt;
[tcpout-server://&amp;lt;receiverip&amp;gt;:9997]&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I checked in splunkd logs in forwarder, there is no error corresponding to tcpout.&lt;BR /&gt;
I am able to telnet on 9997 port from forwarder to receiver&lt;/P&gt;

&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2013 19:22:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/no-forwarder-in-splunk/m-p/78449#M16054</guid>
      <dc:creator>shivanshuk</dc:creator>
      <dc:date>2013-03-28T19:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: no forwarder in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/no-forwarder-in-splunk/m-p/78450#M16055</link>
      <description>&lt;P&gt;i reinstallled splunk and forwarder ,a nd it is working now...&lt;BR /&gt;
seems there was an issue with splunk server configs!!!!!  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2013 10:19:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/no-forwarder-in-splunk/m-p/78450#M16055</guid>
      <dc:creator>shivanshuk</dc:creator>
      <dc:date>2013-04-09T10:19:24Z</dc:date>
    </item>
  </channel>
</rss>

