<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to confirm logs are forwarded from Universal forwarder ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167203#M33845</link>
    <description>&lt;P&gt;This tells you that your forwarder is connect to an indexer, but not if anything was sent.... check out this blog post about last christmas &lt;A href="http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/"&gt;http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 16 May 2014 06:53:20 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-05-16T06:53:20Z</dc:date>
    <item>
      <title>How to confirm logs are forwarded from Universal forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167200#M33842</link>
      <description>&lt;P&gt;Temporarily I dont have access to search head.&lt;BR /&gt;
I had set the inputs.conf to forward windows eventlogs to Splunk indexer.&lt;BR /&gt;
How do i confirm that my logs are forwarded to Splunk indexer from Universal forwarder?&lt;/P&gt;

&lt;P&gt;I tested this :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;gt; splunk list forward-server
Splunk username: admin
Password:*****
Active forwards:
        10.xxx.xxx.xxx:9997
Configured but inactive forwards:
        None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;SO , from this can i confirm logs are forwarded successfully ?&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2014 05:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167200#M33842</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2014-05-16T05:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to confirm logs are forwarded from Universal forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167201#M33843</link>
      <description>&lt;P&gt;How is it that checks by splunkd.log? &lt;BR /&gt;
(ex)&lt;BR /&gt;
05-14-2014 16:09:29.463 +0900 INFO  TcpOutputProc - Connected to idx=10.XXX.XXX.XXX:9997&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2014 06:37:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167201#M33843</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2014-05-16T06:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to confirm logs are forwarded from Universal forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167202#M33844</link>
      <description>&lt;P&gt;05-16-2014 05:46:44.140 +0000 INFO  TcpOutputProc - Connected to idx=10.xxx.xxx.xxx:9997&lt;/P&gt;

&lt;P&gt;Yes , it shows the above&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2014 06:50:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167202#M33844</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2014-05-16T06:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to confirm logs are forwarded from Universal forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167203#M33845</link>
      <description>&lt;P&gt;This tells you that your forwarder is connect to an indexer, but not if anything was sent.... check out this blog post about last christmas &lt;A href="http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/"&gt;http://blogs.splunk.com/2011/01/02/did-i-miss-christmas-2/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 May 2014 06:53:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-confirm-logs-are-forwarded-from-Universal-forwarder/m-p/167203#M33845</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-05-16T06:53:20Z</dc:date>
    </item>
  </channel>
</rss>

