<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Indexer isn't receiving data from the Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114290#M23910</link>
    <description>&lt;P&gt;Just doubled-checked. If data is coming in, it's coming through the Indexer not from the Forwarder.&lt;/P&gt;</description>
    <pubDate>Tue, 19 May 2015 19:06:37 GMT</pubDate>
    <dc:creator>tjohnson2</dc:creator>
    <dc:date>2015-05-19T19:06:37Z</dc:date>
    <item>
      <title>Indexer isn't receiving data from the Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114288#M23908</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I'm having issues receiving data on my Indexer from the Universal Forwarder. Prior to installing the Universal Forwarder, I confirmed that the Indexer was able to receive data. However, after installing the Universal Forwarder and configuring according to Deployment instructions, I confirmed that the Forward-Server was "Active", Netstat was ESTABLISHED on both servers, the Inputs.conf and Outputs.conf files on the Universal Forwarder were configured to receive UDP Traffic and send traffic to the Indexer.  For the purposes of troubleshooting, my OS Firewall has been turned off and I also confirmed that data is showing up in the index= _internal host=forward-server. Data is not updating in the Search Head. Does anyone have any ideas, or know of anything that has been missed.&lt;/P&gt;

&lt;HR /&gt;

&lt;H2&gt;FORWARDER&lt;/H2&gt;

&lt;P&gt;[root@SplunkForwarder bin]# ./splunk list forward-server&lt;BR /&gt;
Active forwards:&lt;BR /&gt;
        10.202.192.33:9997&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;
        None&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;[root@SplunkForwarder local]# more inputs.conf &lt;BR /&gt;
[default]&lt;BR /&gt;
host = Splunk_Forwarder&lt;/P&gt;

&lt;P&gt;[udp://5514]&lt;BR /&gt;
index = pan_logs&lt;BR /&gt;
sourcetype = pan_log&lt;BR /&gt;
connection_host = ip&lt;BR /&gt;
no_appending_timestamp = true&lt;BR /&gt;
disabled = 1&lt;/P&gt;

&lt;P&gt;[udp://514]&lt;/P&gt;

&lt;H2&gt;disabled = false&lt;/H2&gt;

&lt;P&gt;[root@SplunkForwarder local]# more outputs.conf &lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = 10.202.192.33:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://10.202.192.33:9997]&lt;/P&gt;

&lt;HR /&gt;

&lt;H2&gt;INDEXER&lt;/H2&gt;

&lt;P&gt;[root@SplunkLinux bin]# ./splunk display listen&lt;BR /&gt;
Receiving is enabled on port 9997.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:59:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114288#M23908</guid>
      <dc:creator>tjohnson2</dc:creator>
      <dc:date>2020-09-28T19:59:23Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer isn't receiving data from the Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114289#M23909</link>
      <description>&lt;P&gt;Is there really data arriving on port 5514 on the forwarder?&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2015 18:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114289#M23909</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2015-05-19T18:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer isn't receiving data from the Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114290#M23910</link>
      <description>&lt;P&gt;Just doubled-checked. If data is coming in, it's coming through the Indexer not from the Forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2015 19:06:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114290#M23910</guid>
      <dc:creator>tjohnson2</dc:creator>
      <dc:date>2015-05-19T19:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Indexer isn't receiving data from the Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114291#M23911</link>
      <description>&lt;P&gt;Solved my issue by add the information in the location "$SPLUNK_HOME/etc/apps/search/local/inputs.conf"&lt;/P&gt;

&lt;P&gt;This document is also a great resource: &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Useforwardingagentstogetdata"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Useforwardingagentstogetdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2015 20:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Indexer-isn-t-receiving-data-from-the-Universal-Forwarder/m-p/114291#M23911</guid>
      <dc:creator>tjohnson2</dc:creator>
      <dc:date>2015-06-02T20:24:13Z</dc:date>
    </item>
  </channel>
</rss>

