<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot why I am receiving no data from my universal forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160804#M32595</link>
    <description>&lt;P&gt;Thanks Rich.  Firewall isn't the problem.  No local firewall.  Both client and "server" are inside the firewall.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Feb 2015 11:06:05 GMT</pubDate>
    <dc:creator>gfaggiano</dc:creator>
    <dc:date>2015-02-27T11:06:05Z</dc:date>
    <item>
      <title>How to troubleshoot why I am receiving no data from my universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160801#M32592</link>
      <description>&lt;P&gt;Okay...  Here is my hangup.  I've taken some training:&lt;BR /&gt;
-What is Splunk&lt;BR /&gt;
-Searching and Reporting&lt;BR /&gt;
-Building Objects&lt;/P&gt;

&lt;P&gt;But... All my training was dealing with an environment that was already set up and configured.  I have no training for what I'm trying to do!&lt;/P&gt;

&lt;P&gt;So I installed Universal Forwarder (newest available) on a Windows 7 workstation.&lt;BR /&gt;
Default Ports&lt;/P&gt;

&lt;P&gt;I've installed an instance of Splunk Enterprise on another workstation in the same domain.&lt;BR /&gt;
I setup to listen on the same port (9997?)  I can't remember the port number off the top of my head &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;BR /&gt;
I made sure the services were running and did a netstat to make sure the ports were getting through.  all good.&lt;/P&gt;

&lt;P&gt;My problem is that I've tried setting up some data inputs, but i'm not sure I did it correctly because i'm getting no action from the forwarder.&lt;/P&gt;

&lt;P&gt;Here's a simple rundown of what I want to forward (to get me started):&lt;/P&gt;

&lt;P&gt;TCP bytes for:&lt;BR /&gt;
25&lt;BR /&gt;
80&lt;BR /&gt;
110&lt;BR /&gt;
443&lt;BR /&gt;
8080&lt;/P&gt;

&lt;P&gt;UDP bytes for:&lt;BR /&gt;
443&lt;/P&gt;

&lt;P&gt;Any guidance would be great!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2015 18:33:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160801#M32592</guid>
      <dc:creator>gfaggiano</dc:creator>
      <dc:date>2015-02-26T18:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I am receiving no data from my universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160802#M32593</link>
      <description>&lt;P&gt;Make sure Windows Firewall is not blocking the forwarder.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2015 19:39:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160802#M32593</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2015-02-26T19:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I am receiving no data from my universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160803#M32594</link>
      <description>&lt;P&gt;Did you created a outputs.conf file on forwarder to send data to Indexer? If a correct outputs.conf is created, the forwarder should send forwarder's internal logs to your Indexers (without needing to setup an inputs.conf). Once you see internal logs (index=_internal host=yourforwarder), then you can setup data inputs.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Feb 2015 21:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160803#M32594</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-02-26T21:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I am receiving no data from my universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160804#M32595</link>
      <description>&lt;P&gt;Thanks Rich.  Firewall isn't the problem.  No local firewall.  Both client and "server" are inside the firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2015 11:06:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160804#M32595</guid>
      <dc:creator>gfaggiano</dc:creator>
      <dc:date>2015-02-27T11:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I am receiving no data from my universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160805#M32596</link>
      <description>&lt;P&gt;Hi gfaggiano - &lt;/P&gt;

&lt;P&gt;Below link might help you. &lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/218189/forwarders-not-forwarding.html#answer-218190"&gt;http://answers.splunk.com/answers/218189/forwarders-not-forwarding.html#answer-218190&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Feb 2015 11:17:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160805#M32596</guid>
      <dc:creator>satishsdange</dc:creator>
      <dc:date>2015-02-27T11:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I am receiving no data from my universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160806#M32597</link>
      <description>&lt;P&gt;Thank you all for your responses.  I still don't know why the data I requested wasn't sent by the forwarder.  Fortunately, I didn't end up needing it because the same data was coming in from the event logs.  Although I am academically curious, I was able to bring closure to my issue.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2015 12:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160806#M32597</guid>
      <dc:creator>gfaggiano</dc:creator>
      <dc:date>2015-03-02T12:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why I am receiving no data from my universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160807#M32598</link>
      <description>&lt;P&gt;Take a look &lt;A href="http://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs"&gt;here&lt;/A&gt; as well for troubleshooting information.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2015 17:48:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-I-am-receiving-no-data-from-my-universal/m-p/160807#M32598</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2015-03-04T17:48:56Z</dc:date>
    </item>
  </channel>
</rss>

