<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is Universal Forwarder not forwarding? Standard install and all default configuration. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168666#M34141</link>
    <description>&lt;P&gt;Did you actually add any inputs for the UF to read data from?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2013 21:31:37 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2013-12-05T21:31:37Z</dc:date>
    <item>
      <title>Why is Universal Forwarder not forwarding? Standard install and all default configuration.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168665#M34140</link>
      <description>&lt;P&gt;My installation of the Spunk is right out of the box, standard. I followed all the documentation to the letter, used all recommended settings, groups, names, ports, etc.&lt;/P&gt;

&lt;P&gt;In the Splunk interface I configured receiving to listen to 9997. And I installed the Deployment Monitor app.&lt;/P&gt;

&lt;P&gt;I installed the Universal Forwarder on a remote host and selected all the inputs and a directory with a log file. All other the defaults used (also using 9997) &lt;/P&gt;

&lt;P&gt;I verified that the server is reachable and listening on the correct port from the remote host.&lt;/P&gt;

&lt;P&gt;After all this the Deployment monitor still says No forwarders and no data is available in search.&lt;/P&gt;

&lt;P&gt;What am I missing here?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 21:13:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168665#M34140</guid>
      <dc:creator>neiljpeterson</dc:creator>
      <dc:date>2013-12-05T21:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Universal Forwarder not forwarding? Standard install and all default configuration.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168666#M34141</link>
      <description>&lt;P&gt;Did you actually add any inputs for the UF to read data from?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 21:31:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168666#M34141</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-12-05T21:31:37Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Universal Forwarder not forwarding? Standard install and all default configuration.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168667#M34142</link>
      <description>&lt;P&gt;During the installation of UF? Yes I did, I selected all of them and a log file. Changed the post to reflect this.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 21:34:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168667#M34142</guid>
      <dc:creator>neiljpeterson</dc:creator>
      <dc:date>2013-12-05T21:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Universal Forwarder not forwarding? Standard install and all default configuration.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168668#M34143</link>
      <description>&lt;P&gt;Restart the forwarder from a cmd window (run as admin) with  the "c:\program files\splunkuniversalforwarder\bin\splunk.exe  restart" command and look for errors.  If there are none, then shortly after the restart look for errors in the splunk\var\log\splunk\splunkd.log file.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 21:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168668#M34143</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-05T21:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Universal Forwarder not forwarding? Standard install and all default configuration.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168669#M34144</link>
      <description>&lt;P&gt;So I found that the host I was trying to receive data from had been set (possibly inadvertently by me or perhaps by someone else &amp;gt;:|) as another indexer to also send data to. I guess this caused a conflict in some way?&lt;/P&gt;

&lt;P&gt;After I removed that configuration and restarted Splunk the host's data is now showing up!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2013 22:16:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168669#M34144</guid>
      <dc:creator>neiljpeterson</dc:creator>
      <dc:date>2013-12-05T22:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Universal Forwarder not forwarding? Standard install and all default configuration.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168670#M34145</link>
      <description>&lt;P&gt;Beware the 'other' admins.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2013 00:57:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Universal-Forwarder-not-forwarding-Standard-install-and/m-p/168670#M34145</guid>
      <dc:creator>lukejadamec</dc:creator>
      <dc:date>2013-12-06T00:57:24Z</dc:date>
    </item>
  </channel>
</rss>

