<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is Splunk forwarder is not forwarding events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181434#M36387</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have installed Splunk to forward audit logs from LDAP to server02 and are not getting any events from the server.  The logs are filtered and forwarded correctly to server01 just not to server02. Is this because server02 is not defined in the defaultgroup ? &lt;/P&gt;

&lt;P&gt;Please advice.&lt;/P&gt;

&lt;P&gt;Here are the configuration files.&lt;/P&gt;

&lt;P&gt;Inputs.conf (Entry)&lt;BR /&gt;
[monitor:///logsa/audit.log]&lt;BR /&gt;
source = IT-LDAP-audit-ldapdb2&lt;BR /&gt;
sourcetype = IT-LDAP-audit_entry&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;Outputs.conf&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-clone-group-server01_9997&lt;BR /&gt;
disabled = false&lt;BR /&gt;
isLoadBalanced = False&lt;BR /&gt;
maxQueueSize = 1000&lt;BR /&gt;
indexAndForward = false&lt;/P&gt;

&lt;P&gt;[tcpout:server02_1536]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
server = server02.com:1536&lt;/P&gt;

&lt;P&gt;[props.conf]&lt;BR /&gt;
[IT-LDAP-audit_entry]&lt;BR /&gt;
TIME_PREFIX = ^AuditV3--&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%d-%H:%M:%S&lt;BR /&gt;
TZ = US/Eastern&lt;BR /&gt;
BREAK_ONLY_BEFORE = ^AuditV3--&lt;BR /&gt;
TRANSFORMS-skip = knownldapaudit&lt;BR /&gt;
TRANSFORMS-routing = arcsightldapnp&lt;/P&gt;

&lt;P&gt;[transform.conf]&lt;BR /&gt;
[arcsightldapnp]&lt;BR /&gt;
REGEX = Invalid credentials&lt;BR /&gt;
DEST_KEY = _TCP_ROUTING&lt;BR /&gt;
FORMAT = arcsightldapnpreader&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 17:20:07 GMT</pubDate>
    <dc:creator>kvmuralidhar</dc:creator>
    <dc:date>2020-09-28T17:20:07Z</dc:date>
    <item>
      <title>Why is Splunk forwarder is not forwarding events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181434#M36387</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have installed Splunk to forward audit logs from LDAP to server02 and are not getting any events from the server.  The logs are filtered and forwarded correctly to server01 just not to server02. Is this because server02 is not defined in the defaultgroup ? &lt;/P&gt;

&lt;P&gt;Please advice.&lt;/P&gt;

&lt;P&gt;Here are the configuration files.&lt;/P&gt;

&lt;P&gt;Inputs.conf (Entry)&lt;BR /&gt;
[monitor:///logsa/audit.log]&lt;BR /&gt;
source = IT-LDAP-audit-ldapdb2&lt;BR /&gt;
sourcetype = IT-LDAP-audit_entry&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;Outputs.conf&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup = default-clone-group-server01_9997&lt;BR /&gt;
disabled = false&lt;BR /&gt;
isLoadBalanced = False&lt;BR /&gt;
maxQueueSize = 1000&lt;BR /&gt;
indexAndForward = false&lt;/P&gt;

&lt;P&gt;[tcpout:server02_1536]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
server = server02.com:1536&lt;/P&gt;

&lt;P&gt;[props.conf]&lt;BR /&gt;
[IT-LDAP-audit_entry]&lt;BR /&gt;
TIME_PREFIX = ^AuditV3--&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%d-%H:%M:%S&lt;BR /&gt;
TZ = US/Eastern&lt;BR /&gt;
BREAK_ONLY_BEFORE = ^AuditV3--&lt;BR /&gt;
TRANSFORMS-skip = knownldapaudit&lt;BR /&gt;
TRANSFORMS-routing = arcsightldapnp&lt;/P&gt;

&lt;P&gt;[transform.conf]&lt;BR /&gt;
[arcsightldapnp]&lt;BR /&gt;
REGEX = Invalid credentials&lt;BR /&gt;
DEST_KEY = _TCP_ROUTING&lt;BR /&gt;
FORMAT = arcsightldapnpreader&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:20:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181434#M36387</guid>
      <dc:creator>kvmuralidhar</dc:creator>
      <dc:date>2020-09-28T17:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk forwarder is not forwarding events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181435#M36388</link>
      <description>&lt;P&gt;Yes you need to specify  it in default group. &lt;/P&gt;

&lt;P&gt;Splunk documentation says -- * Starting with 4.2, this attribute is no longer required. But somehow this doesn't work. &lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2014 11:21:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181435#M36388</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-14T11:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk forwarder is not forwarding events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181436#M36389</link>
      <description>&lt;P&gt;Hi Strive,&lt;/P&gt;

&lt;P&gt;Thank your for your quick response.&lt;/P&gt;

&lt;P&gt;Murali&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2014 11:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181436#M36389</guid>
      <dc:creator>kvmuralidhar</dc:creator>
      <dc:date>2014-08-14T11:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk forwarder is not forwarding events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181437#M36390</link>
      <description>&lt;P&gt;Did it work?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Aug 2014 12:20:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181437#M36390</guid>
      <dc:creator>strive</dc:creator>
      <dc:date>2014-08-14T12:20:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why is Splunk forwarder is not forwarding events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181438#M36391</link>
      <description>&lt;P&gt;Hi Steve,&lt;/P&gt;

&lt;P&gt;Sorry for the delayed response.  It did not work.  Here is the relevant info from props.conf, outputs.conf, &amp;amp; transforms.conf file.&lt;/P&gt;

&lt;P&gt;props.conf entry&lt;BR /&gt;
[IT-LDAP-audit_entry]&lt;BR /&gt;
TIME_PREFIX = ^AuditV3--&lt;BR /&gt;
TIME_FORMAT = %Y-%m-%d-%H:%M:%S&lt;BR /&gt;
TZ = US/Eastern&lt;BR /&gt;
BREAK_ONLY_BEFORE = ^AuditV3--&lt;BR /&gt;
TRANSFORMS-routing = arcsightldapnp&lt;/P&gt;

&lt;P&gt;Transforms.conf entry&lt;BR /&gt;
[arcsightldapnp]&lt;BR /&gt;
REGEX = .&lt;BR /&gt;
DEST_KEY = _TCP_ROUTING&lt;BR /&gt;
FORMAT = arcsightldapnpreader&lt;/P&gt;

&lt;P&gt;Outputs.conf&lt;/P&gt;

&lt;P&gt;[tcpout:arcsightldapnpreader]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
server = servername:1536&lt;/P&gt;

&lt;P&gt;Thanks in advance for your help&lt;/P&gt;

&lt;P&gt;Murali&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 17:24:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-Splunk-forwarder-is-not-forwarding-events/m-p/181438#M36391</guid>
      <dc:creator>kvmuralidhar</dc:creator>
      <dc:date>2020-09-28T17:24:08Z</dc:date>
    </item>
  </channel>
</rss>

