<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk storm forwarder indexer configuration in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85104#M17709</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I am a novice splunk storm user and just installed the universal forwarder. But the installation expects a indexer ipaddress. I assumed as I was using splunk storm that I don't need to give this... its known by the installation. After installation, I ran the command "&lt;CODE&gt;splunk.exe list forward-server&lt;/CODE&gt;" and get :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Active forwards:
        None
Configured but inactive forwards:
        forwarder.splunkstorm.com:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I tried telneting to forwarder.splunkstorm.com at port 9997 but that fails. Is this something to setup in splunk storm itself?&lt;/P&gt;

&lt;P&gt;Appreciate any help.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sudarshan&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jan 2013 16:51:05 GMT</pubDate>
    <dc:creator>lsudarshan</dc:creator>
    <dc:date>2013-01-11T16:51:05Z</dc:date>
    <item>
      <title>Splunk storm forwarder indexer configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85104#M17709</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;

&lt;P&gt;I am a novice splunk storm user and just installed the universal forwarder. But the installation expects a indexer ipaddress. I assumed as I was using splunk storm that I don't need to give this... its known by the installation. After installation, I ran the command "&lt;CODE&gt;splunk.exe list forward-server&lt;/CODE&gt;" and get :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Active forwards:
        None
Configured but inactive forwards:
        forwarder.splunkstorm.com:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I tried telneting to forwarder.splunkstorm.com at port 9997 but that fails. Is this something to setup in splunk storm itself?&lt;/P&gt;

&lt;P&gt;Appreciate any help.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sudarshan&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 16:51:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85104#M17709</guid>
      <dc:creator>lsudarshan</dc:creator>
      <dc:date>2013-01-11T16:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk storm forwarder indexer configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85105#M17710</link>
      <description>&lt;P&gt;Did you start by downloading the credentials package from within your Splunk Storm project? See &lt;A href="http://docs.splunk.com/Documentation/Storm/latest/User/SetupauniversalforwarderonWindows"&gt;Set up a universal forwarder on Windows&lt;/A&gt; in the Splunk Storm documentation.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 21:26:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85105#M17710</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2013-01-11T21:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk storm forwarder indexer configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85106#M17711</link>
      <description>&lt;P&gt;These should help you.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/58868/splunk-storm-trouble-adding-forwarders"&gt;http://splunk-base.splunk.com/answers/58868/splunk-storm-trouble-adding-forwarders&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/58992/datas-are-not-sent-from-my-machine-to-splunk-strom-web-ui"&gt;http://splunk-base.splunk.com/answers/58992/datas-are-not-sent-from-my-machine-to-splunk-strom-web-ui&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 21:28:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85106#M17711</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2013-01-11T21:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk storm forwarder indexer configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85107#M17712</link>
      <description>&lt;P&gt;Thanks for the answer Chris. I did indeed install the credentials package which created  an app under the forwarder. But the command "splunk.exe list forward-server" still gives :&lt;/P&gt;

&lt;P&gt;Active forwards:&lt;BR /&gt;
        None&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;
        forwarder.splunkstorm.com:9997&lt;/P&gt;

&lt;P&gt;The curious thing is I can't telnet to forwarder.splunkstorm.com at port 9997.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 22:31:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85107#M17712</guid>
      <dc:creator>lsudarshan</dc:creator>
      <dc:date>2013-01-11T22:31:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk storm forwarder indexer configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85108#M17713</link>
      <description>&lt;P&gt;Hm, then yeah, your firewall might be blocking something, or you might have a port issue from some setting in the AWS management console (see the first posting sdaniels listed). And you need to tell the forwarder what to monitor (see YannK's answer in the second posting that sdaniels listed). Beyond that, someone with deeper knowledge is going to have to help you here!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jan 2013 22:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85108#M17713</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2013-01-11T22:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk storm forwarder indexer configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85109#M17714</link>
      <description>&lt;P&gt;Thanks Chris... will try it out.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2013 10:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85109#M17714</guid>
      <dc:creator>lsudarshan</dc:creator>
      <dc:date>2013-01-12T10:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk storm forwarder indexer configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85110#M17715</link>
      <description>&lt;P&gt;Thanks sdaniels. Will try these suggestions.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Jan 2013 10:57:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85110#M17715</guid>
      <dc:creator>lsudarshan</dc:creator>
      <dc:date>2013-01-12T10:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk storm forwarder indexer configuration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85111#M17716</link>
      <description>&lt;P&gt;I've solved this by allowing the port 9997 on firewall.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sudo ufw allow 9997
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 02 Mar 2013 21:09:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-storm-forwarder-indexer-configuration/m-p/85111#M17716</guid>
      <dc:creator>colares</dc:creator>
      <dc:date>2013-03-02T21:09:37Z</dc:date>
    </item>
  </channel>
</rss>

