<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130791#M26871</link>
    <description>&lt;P&gt;Now with the new version of Splunk, you can get your Forwarder Configuration app right from the GUI.   It contains all the settings to setup security and tell the forwarder where to send your machine data.&lt;/P&gt;

&lt;P&gt;From the Launcher app (default landing page)&lt;/P&gt;

&lt;P&gt;Look on the left of the screen and click the forwarder app&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/219i864193EDB749ABDB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;From there  you will download your forwarder config app.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/220i7A5BA8ED07E5FECB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Follow the instructions and you are good to go.&lt;/P&gt;

&lt;P&gt;Inside there are a bunch of files, but notice the outputs.conf, and see the server= setting on the line below. So you aren’t using the same FQDN as you use for the UI.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = splunkcloud

[tcpout:splunkcloud]
compressed = false
disabled = false
server = input-blah.cloud.splunk.com:9997
sslCommonNameToCheck = blah.cloud.splunk.com
sslCertPath = $SPLUNK_HOME/etc/apps/splunkclouduf/default/client.pem
sslPassword = fdf1c4601674ddd5fca3db0486d927db
sslRootCAPath = $SPLUNK_HOME/etc/apps/splunkclouduf/default/cacert.pem
sslVerifyServerCert = true
useACK = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Give that a whirl and let me know what you think.  &lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Kyle&lt;/P&gt;

&lt;P&gt;PS One note on WINDOWS forwarders.  During installation, the wizard asks you to enter Deployment Server and Receiving Indexer FQDNs or IPs. &lt;STRONG&gt;LEAVE THEM BLANK.&lt;/STRONG&gt;&lt;BR /&gt;
The .spl package will configure your receiving indexer(s) for you, and unless you have an on premise DS, then leave it blank.  Else, your data will never show up and you will be unhappy.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Feb 2015 01:01:07 GMT</pubDate>
    <dc:creator>khourihan_splun</dc:creator>
    <dc:date>2015-02-05T01:01:07Z</dc:date>
    <item>
      <title>How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130790#M26870</link>
      <description>&lt;P&gt;I've noticed customers having problems with the current 6.2.1 Online Sandboxes.  As of last month, the UI has changed significantly with the new upgrade.&lt;/P&gt;

&lt;P&gt;Customers used to have to manually enter their outputs.conf, but thats changed now.  How do you do it?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2015 00:48:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130790#M26870</guid>
      <dc:creator>khourihan_splun</dc:creator>
      <dc:date>2015-02-05T00:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130791#M26871</link>
      <description>&lt;P&gt;Now with the new version of Splunk, you can get your Forwarder Configuration app right from the GUI.   It contains all the settings to setup security and tell the forwarder where to send your machine data.&lt;/P&gt;

&lt;P&gt;From the Launcher app (default landing page)&lt;/P&gt;

&lt;P&gt;Look on the left of the screen and click the forwarder app&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/219i864193EDB749ABDB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;From there  you will download your forwarder config app.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/220i7A5BA8ED07E5FECB/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Follow the instructions and you are good to go.&lt;/P&gt;

&lt;P&gt;Inside there are a bunch of files, but notice the outputs.conf, and see the server= setting on the line below. So you aren’t using the same FQDN as you use for the UI.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = splunkcloud

[tcpout:splunkcloud]
compressed = false
disabled = false
server = input-blah.cloud.splunk.com:9997
sslCommonNameToCheck = blah.cloud.splunk.com
sslCertPath = $SPLUNK_HOME/etc/apps/splunkclouduf/default/client.pem
sslPassword = fdf1c4601674ddd5fca3db0486d927db
sslRootCAPath = $SPLUNK_HOME/etc/apps/splunkclouduf/default/cacert.pem
sslVerifyServerCert = true
useACK = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Give that a whirl and let me know what you think.  &lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Kyle&lt;/P&gt;

&lt;P&gt;PS One note on WINDOWS forwarders.  During installation, the wizard asks you to enter Deployment Server and Receiving Indexer FQDNs or IPs. &lt;STRONG&gt;LEAVE THEM BLANK.&lt;/STRONG&gt;&lt;BR /&gt;
The .spl package will configure your receiving indexer(s) for you, and unless you have an on premise DS, then leave it blank.  Else, your data will never show up and you will be unhappy.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2015 01:01:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130791#M26871</guid>
      <dc:creator>khourihan_splun</dc:creator>
      <dc:date>2015-02-05T01:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130792#M26872</link>
      <description>&lt;P&gt;Does this also work on windows?&lt;BR /&gt;
What are the commands I should run? (instead of the *nix paths)&lt;BR /&gt;
How do I know if it worked?&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2015 10:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130792#M26872</guid>
      <dc:creator>malkiz_walkme</dc:creator>
      <dc:date>2015-03-19T10:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130793#M26873</link>
      <description>&lt;P&gt;Wow, the confusion and major lack of user friendly install directions is terrible.  I considered using Splunk, but I've spent more time trying to install/configure for this Sandbox that it's no longer worth my time.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 17:04:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130793#M26873</guid>
      <dc:creator>delzinga</dc:creator>
      <dc:date>2015-06-09T17:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130794#M26874</link>
      <description>&lt;P&gt;Yes, it works on Windows too.  Just run the same &lt;CODE&gt;splunk install app&lt;/CODE&gt; from the "&lt;CODE&gt;C:Program Files\\splunkforwarder\\bin&lt;/CODE&gt;" directory (or wherever %SPLUNK_HOME%\\bin lives. &lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 18:23:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130794#M26874</guid>
      <dc:creator>khourihan_splun</dc:creator>
      <dc:date>2015-06-09T18:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130795#M26875</link>
      <description>&lt;P&gt;note this app took out the backslashes, but you should not. &lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 18:25:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130795#M26875</guid>
      <dc:creator>khourihan_splun</dc:creator>
      <dc:date>2015-06-09T18:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130796#M26876</link>
      <description>&lt;P&gt;Odd, this did nothing when I ran it.  no output at all and none of my outputs.conf files were edited.  there seem to be no actual windows commands in the docs.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2015 15:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130796#M26876</guid>
      <dc:creator>Cuyose</dc:creator>
      <dc:date>2015-09-23T15:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130797#M26877</link>
      <description>&lt;P&gt;@Cuyose can make a diag and create a ticket and upload it? PM me at &lt;A href="mailto:kyle@splunk.com"&gt;kyle@splunk.com&lt;/A&gt; the case # and we can take a look.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2015 18:10:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130797#M26877</guid>
      <dc:creator>khourihan_splun</dc:creator>
      <dc:date>2015-09-25T18:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: How do I set up a Splunk Cloud Trial (Sandbox) Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130798#M26878</link>
      <description>&lt;P&gt;Doesnt seem to work for me.&lt;BR /&gt;
This is what I see in the log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-03-2017 15:38:31.923 +0000 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected
04-03-2017 15:38:34.429 +0000 WARN  HttpPubSubConnection - Unable to parse message from PubSubSvr: 
04-03-2017 15:38:34.429 +0000 INFO  HttpPubSubConnection - Could not obtain connection, will retry after=32.804 seconds.
04-03-2017 15:38:43.923 +0000 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected
04-03-2017 15:38:55.923 +0000 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected
04-03-2017 15:38:57.482 +0000 ERROR TcpOutputFd - Connection to host=52.201.237.113:9997 failed. sock_error = 104. SSL Error = error:00000000:lib(0):func(0):reason(0)
04-03-2017 15:39:07.441 +0000 WARN  HttpPubSubConnection - Unable to parse message from PubSubSvr: 
04-03-2017 15:39:07.442 +0000 INFO  HttpPubSubConnection - Could not obtain connection, will retry after=63.757 seconds.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I tried telnet to the IP &amp;amp; port, and that seems to go through.&lt;/P&gt;

&lt;P&gt;Missed mentioning that this is on ubuntu.&lt;/P&gt;

&lt;H1&gt;The outputs.conf is:&lt;/H1&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = splunkcloud&lt;/P&gt;

&lt;P&gt;[tcpout:splunkcloud]&lt;BR /&gt;
compressed = false&lt;BR /&gt;
disabled = false&lt;BR /&gt;
server = input-prd-p-h3z7wk2hxjrm.cloud.splunk.com:9997&lt;BR /&gt;
sslCommonNameToCheck = input-prd-p-h3z7wk2hxjrm.cloud.splunk.com&lt;BR /&gt;
sslCertPath = $SPLUNK_HOME/etc/apps/splunkclouduf/default/client.pem&lt;BR /&gt;
sslPassword = 8997f53906a6bc9140a895e78335143b&lt;BR /&gt;
sslRootCAPath = $SPLUNK_HOME/etc/apps/splunkclouduf/default/cacert.pem&lt;BR /&gt;
sslVerifyServerCert = true&lt;/P&gt;

&lt;H1&gt;useACK = true&lt;/H1&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:26:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-set-up-a-Splunk-Cloud-Trial-Sandbox-Forwarder/m-p/130798#M26878</guid>
      <dc:creator>avaikar</dc:creator>
      <dc:date>2020-09-29T13:26:55Z</dc:date>
    </item>
  </channel>
</rss>

