<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk not receiving data from windows universal forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-not-receiving-data-from-windows-universal-forwarder/m-p/116764#M24348</link>
    <description>&lt;P&gt;Installed universal forwarder in windows. Checked the splunkd log and I could see the connection to server without any error as below. tried checking with firewall and ports.But still index doesnt log any events. &lt;/P&gt;

&lt;P&gt;TcpOutputProc - Connected to idx=xxxx:9997.&lt;/P&gt;

&lt;P&gt;Below are my conf file.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;inputs.conf
[default]
host = xxxxx
[monitor:C:\opt\splunk\]
disabled = false
sourcetype = hievents
index = hiindex


Outputs.conf
[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = xxxx:9997

[tcpout-server://xxxx:9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please advice.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jun 2014 06:32:51 GMT</pubDate>
    <dc:creator>skumarvs</dc:creator>
    <dc:date>2014-06-24T06:32:51Z</dc:date>
    <item>
      <title>splunk not receiving data from windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-not-receiving-data-from-windows-universal-forwarder/m-p/116764#M24348</link>
      <description>&lt;P&gt;Installed universal forwarder in windows. Checked the splunkd log and I could see the connection to server without any error as below. tried checking with firewall and ports.But still index doesnt log any events. &lt;/P&gt;

&lt;P&gt;TcpOutputProc - Connected to idx=xxxx:9997.&lt;/P&gt;

&lt;P&gt;Below are my conf file.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;inputs.conf
[default]
host = xxxxx
[monitor:C:\opt\splunk\]
disabled = false
sourcetype = hievents
index = hiindex


Outputs.conf
[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = xxxx:9997

[tcpout-server://xxxx:9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please advice.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2014 06:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-not-receiving-data-from-windows-universal-forwarder/m-p/116764#M24348</guid>
      <dc:creator>skumarvs</dc:creator>
      <dc:date>2014-06-24T06:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not receiving data from windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-not-receiving-data-from-windows-universal-forwarder/m-p/116765#M24349</link>
      <description>&lt;P&gt;Hi skumarvs,&lt;/P&gt;

&lt;P&gt;here are some typical troubleshooting tips:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Do you search the correct time range - try all time?&lt;/LI&gt;
&lt;LI&gt;Do you search the correct index - try &lt;CODE&gt;index=hiindex&lt;/CODE&gt;?&lt;/LI&gt;
&lt;LI&gt;Do you have permission to search this index?&lt;/LI&gt;
&lt;LI&gt;search &lt;CODE&gt;index=_internal source=*splunkd.log&lt;/CODE&gt; on the indexer for any error related to the universal forwarder&lt;/LI&gt;
&lt;LI&gt;run a snoop/tcpdump to ensure there is something sent to the indexer, if the universal forwarder tells you it is connected that does not mean it sends data.&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Last but not least do the usual troubleshooting around Splunk, is everything doing what it should do and so on.&lt;/P&gt;

&lt;P&gt;hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2014 06:53:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-not-receiving-data-from-windows-universal-forwarder/m-p/116765#M24349</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-24T06:53:03Z</dc:date>
    </item>
    <item>
      <title>Re: splunk not receiving data from windows universal forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-not-receiving-data-from-windows-universal-forwarder/m-p/116766#M24350</link>
      <description>&lt;P&gt;Please check for monitor syntax: [monitor://&lt;PATH&gt;]&lt;/PATH&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2014 09:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-not-receiving-data-from-windows-universal-forwarder/m-p/116766#M24350</guid>
      <dc:creator>ankireddy007</dc:creator>
      <dc:date>2014-06-24T09:52:31Z</dc:date>
    </item>
  </channel>
</rss>

