<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to get universal forwarder to become active - Linux in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-universal-forwarder-to-become-active-Linux/m-p/91822#M19092</link>
    <description>&lt;UL&gt;
&lt;LI&gt;The unix inputs goes to the "os" index by default, check in every indexes with index=*.&lt;/LI&gt;
&lt;LI&gt;the UF have a slow thruput by default, it may still be forwarding old logs.&lt;/LI&gt;
&lt;LI&gt;when you opened the port 9997 on the indexer, was it as tcp ( in the inputs manager), or as splunktcp (in the forward and received manager) ? The correct one is the second and look like &lt;CODE&gt;[splunktcp://9997]&lt;/CODE&gt; in inputs.conf&lt;/LI&gt;
&lt;LI&gt;no firewall ? try a &lt;CODE&gt;telnet redactedservername 9997&lt;/CODE&gt; from the forwarders&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;finally, read the logs in $SPLUNK_HOME/var/log/splunk/splunkd.log in both side.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Oct 2012 15:44:56 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2012-10-16T15:44:56Z</dc:date>
    <item>
      <title>Unable to get universal forwarder to become active - Linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-universal-forwarder-to-become-active-Linux/m-p/91821#M19091</link>
      <description>&lt;P&gt;Hi, I have configured a basic splunk instance and it is indexing locally. I wanted to add a universal forwarder from another linux server and have the *nix app forward to the indexer.  I have configured a data input on the indexer on port 9997 which shows as active (I checked it with strobe from another machine).&lt;/P&gt;

&lt;P&gt;I installed the universal forwarder on a different server and set up the indexer as the forward server.  It shows as inactive.&lt;BR /&gt;
/opt/splunkforwarder/bin # ./splunk list forward-server&lt;BR /&gt;
Your session is invalid.  Please login.&lt;BR /&gt;
Splunk username: admin&lt;BR /&gt;
Password: &lt;BR /&gt;
Active forwards:&lt;BR /&gt;
    None&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;
    &lt;SERVERNAME redacted=""&gt;:9997&lt;/SERVERNAME&gt;&lt;/P&gt;

&lt;P&gt;Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2012 15:21:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-universal-forwarder-to-become-active-Linux/m-p/91821#M19091</guid>
      <dc:creator>jplangan</dc:creator>
      <dc:date>2012-10-16T15:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get universal forwarder to become active - Linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-universal-forwarder-to-become-active-Linux/m-p/91822#M19092</link>
      <description>&lt;UL&gt;
&lt;LI&gt;The unix inputs goes to the "os" index by default, check in every indexes with index=*.&lt;/LI&gt;
&lt;LI&gt;the UF have a slow thruput by default, it may still be forwarding old logs.&lt;/LI&gt;
&lt;LI&gt;when you opened the port 9997 on the indexer, was it as tcp ( in the inputs manager), or as splunktcp (in the forward and received manager) ? The correct one is the second and look like &lt;CODE&gt;[splunktcp://9997]&lt;/CODE&gt; in inputs.conf&lt;/LI&gt;
&lt;LI&gt;no firewall ? try a &lt;CODE&gt;telnet redactedservername 9997&lt;/CODE&gt; from the forwarders&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;finally, read the logs in $SPLUNK_HOME/var/log/splunk/splunkd.log in both side.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2012 15:44:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-universal-forwarder-to-become-active-Linux/m-p/91822#M19092</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-10-16T15:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to get universal forwarder to become active - Linux</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-universal-forwarder-to-become-active-Linux/m-p/91823#M19093</link>
      <description>&lt;P&gt;I used the wrong place to configure the receiving port.  I needed to use Manager &amp;gt;&amp;gt; Forwarding and receiving &amp;gt;&amp;gt;Configure Receiving to configure it.  It does now say that the forwarder is active.&lt;/P&gt;

&lt;P&gt;I need to tell the forwarder what to send now, somehow.  &lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2012 15:55:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-get-universal-forwarder-to-become-active-Linux/m-p/91823#M19093</guid>
      <dc:creator>jplangan</dc:creator>
      <dc:date>2012-10-16T15:55:27Z</dc:date>
    </item>
  </channel>
</rss>

