<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Universal Forwarder - basic Windows install in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131830#M27116</link>
    <description>&lt;P&gt;I don't think the dc_bind would prevent receipt of events.&lt;/P&gt;

&lt;P&gt;Are you sure your receivers are able to receive events? Are you receiving events from other host types?  Have you enabled receiving?  On same port specified by client? &lt;/P&gt;

&lt;P&gt;Run ".\bin\splunk cmd btool outputs list" from the command line on your windows client.  Are the correct server names:ports specified?  Can you reach those server names:ports from client via ping and telnet?  &lt;/P&gt;</description>
    <pubDate>Sun, 06 Jul 2014 13:07:31 GMT</pubDate>
    <dc:creator>dstaulcu</dc:creator>
    <dc:date>2014-07-06T13:07:31Z</dc:date>
    <item>
      <title>Splunk Universal Forwarder - basic Windows install</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131829#M27115</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;

&lt;P&gt;I've just manually installed our first Windows-based Splunk Universal Forwarder. I checked the boxes asking for various Windows event logs, and opted-in to the Windows extension it suggests.&lt;/P&gt;

&lt;P&gt;However, I can't get it forwarding to splunk. The machine itself can connect on port 8089 to the deployment server specified. Looking in the logs, I see an entry with&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;07-06-2014 12:39:02.186 +0000 ERROR TcpOutputProc - LightWeightForwarder/UniversalForwarder not configured. Please configure outputs.conf.
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::bind: Failed to get domain controller name with DsGetDcName: (1355)
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::bind: Failed to get domain controller name with DsGetDcName: (1355)
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::bind: Failed to get domain controller name with DsGetDcName: (1355)
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::connectToDC: DsBind failed: (1355)
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventLogChannel::init: Failed to bind to DC, dc_bind_time=0 msec
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::connectToDC: DsBind failed: (1355)
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - EvtDC::connectToDC: DsBind failed: (1355)
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventLogChannel::init: Failed to bind to DC, dc_bind_time=0 msec
07-06-2014 12:39:08.083 +0000 ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventLogChannel::init: Failed to bind to DC, dc_bind_time=0 msec
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, my understanding was the default windows install should be configuring outputs.conf for me? Also, I'm not sure whether the DC binding errors matter (this machine isn't on a domain). Any idea what's going wrong?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jul 2014 12:32:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131829#M27115</guid>
      <dc:creator>jamescrowley</dc:creator>
      <dc:date>2014-07-06T12:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder - basic Windows install</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131830#M27116</link>
      <description>&lt;P&gt;I don't think the dc_bind would prevent receipt of events.&lt;/P&gt;

&lt;P&gt;Are you sure your receivers are able to receive events? Are you receiving events from other host types?  Have you enabled receiving?  On same port specified by client? &lt;/P&gt;

&lt;P&gt;Run ".\bin\splunk cmd btool outputs list" from the command line on your windows client.  Are the correct server names:ports specified?  Can you reach those server names:ports from client via ping and telnet?  &lt;/P&gt;</description>
      <pubDate>Sun, 06 Jul 2014 13:07:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131830#M27116</guid>
      <dc:creator>dstaulcu</dc:creator>
      <dc:date>2014-07-06T13:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder - basic Windows install</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131831#M27117</link>
      <description>&lt;P&gt;I just have a standard Splunk install running on a Linux AMI (basic install using the rpm package). The port is definitely accessible and accepting connections.&lt;/P&gt;

&lt;P&gt;On the windows machine, I have &lt;/P&gt;

&lt;P&gt;[target-broker:deploymentServer]&lt;BR /&gt;
targetUri = XXXX:8089&lt;/P&gt;

&lt;P&gt;set in /etc/system/local/deploymentclient.conf&lt;/P&gt;

&lt;P&gt;I also ran btool outputs list (wasn't quite sure which command you wanted me to run), which just has a [tcpout] section (I'd list here but comments have a max length it seems??)&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jul 2014 13:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131831#M27117</guid>
      <dc:creator>jamescrowley</dc:creator>
      <dc:date>2014-07-06T13:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder - basic Windows install</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131832#M27118</link>
      <description>&lt;P&gt;All the settings being listed by btool appear to come from &lt;/P&gt;

&lt;P&gt;etc/system/default/outputs.conf&lt;/P&gt;

&lt;P&gt;There is &lt;EM&gt;no&lt;/EM&gt; outputs.conf in etc/system/local. Should there be? And if so, any idea why the installer hasn't added it? Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jul 2014 13:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131832#M27118</guid>
      <dc:creator>jamescrowley</dc:creator>
      <dc:date>2014-07-06T13:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder - basic Windows install</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131833#M27119</link>
      <description>&lt;P&gt;I don't recall where it should be by virtue of the specification via installer.  What I do remember of use of specification of confs via installer is that the installer places the confs in a location which is difficult to manage (override) over time.  Better to specify only deploymentclient details (use a DNS alias) via installer and to have the deploymentclient download desired deployment-apps (outputs, inputs) on first phoneHome.  &lt;/P&gt;

&lt;P&gt;Save yourself some trouble down the road and take this opportunity to push your desired inputs/outputs via deployment server instead of relying on installer to do so.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jul 2014 13:46:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131833#M27119</guid>
      <dc:creator>dstaulcu</dc:creator>
      <dc:date>2014-07-06T13:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder - basic Windows install</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131834#M27120</link>
      <description>&lt;P&gt;Sorry @dstaulcu if I'm missing something here - but specifying the deployment client (IP + port) is the only thing I &lt;EM&gt;have&lt;/EM&gt; done during the install of the universal forwarder? I haven't touched anything else? That's why I'm struggling to understand what's going wrong here&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jul 2014 14:17:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131834#M27120</guid>
      <dc:creator>jamescrowley</dc:creator>
      <dc:date>2014-07-06T14:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Universal Forwarder - basic Windows install</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131835#M27121</link>
      <description>&lt;P&gt;Yes. There should be configuration details in outputs.conf describing the server(s) to which events should be sent.   &lt;/P&gt;

&lt;P&gt;You can find the spec for outputs.conf here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.1.1/Admin/Outputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.1.1/Admin/Outputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;At the bottom of the outputs.conf spec file you will find examples showing the minimum info needed.&lt;/P&gt;

&lt;P&gt;The splunk universal for windows has default inputs which are routed to the _internal index.&lt;/P&gt;

&lt;P&gt;Once you get outputs functioning you can go to your search head and search index=_internal host="yourwindowshostname" to verify that events are searchable&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jul 2014 14:26:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Universal-Forwarder-basic-Windows-install/m-p/131835#M27121</guid>
      <dc:creator>dstaulcu</dc:creator>
      <dc:date>2014-07-06T14:26:39Z</dc:date>
    </item>
  </channel>
</rss>

