<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to forward data from Universal Forwarder into online sandbox instance in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186254#M37308</link>
    <description>&lt;P&gt;Here are the steps to configure your Universal Forwarder to forward events to your online sandbox instance:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Enable receiver in your online sandbox instance in &lt;A href="https://prd-something-something.splunk6.splunktrial.com/en-US/manager/search/data/inputs/tcp/cooked"&gt;https://prd-something-something.splunk6.splunktrial.com/en-US/manager/search/data/inputs/tcp/cooked&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Then configure your Universal Forwarder with the following commands: &lt;/P&gt;

&lt;P&gt;./splunk add forward-server input-prd-something-something.splunk6.splunktrial.com:9997&lt;BR /&gt;
./splunk add monitor &lt;SAMPLE_LOG_FILE&gt;&lt;BR /&gt;
Now perform a search and you'll be able to see some events in your online sandbox instance&lt;/SAMPLE_LOG_FILE&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Sun, 26 Oct 2014 22:33:19 GMT</pubDate>
    <dc:creator>Nicholas_Key</dc:creator>
    <dc:date>2014-10-26T22:33:19Z</dc:date>
    <item>
      <title>How to forward data from Universal Forwarder into online sandbox instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186254#M37308</link>
      <description>&lt;P&gt;Here are the steps to configure your Universal Forwarder to forward events to your online sandbox instance:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Enable receiver in your online sandbox instance in &lt;A href="https://prd-something-something.splunk6.splunktrial.com/en-US/manager/search/data/inputs/tcp/cooked"&gt;https://prd-something-something.splunk6.splunktrial.com/en-US/manager/search/data/inputs/tcp/cooked&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Then configure your Universal Forwarder with the following commands: &lt;/P&gt;

&lt;P&gt;./splunk add forward-server input-prd-something-something.splunk6.splunktrial.com:9997&lt;BR /&gt;
./splunk add monitor &lt;SAMPLE_LOG_FILE&gt;&lt;BR /&gt;
Now perform a search and you'll be able to see some events in your online sandbox instance&lt;/SAMPLE_LOG_FILE&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Sun, 26 Oct 2014 22:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186254#M37308</guid>
      <dc:creator>Nicholas_Key</dc:creator>
      <dc:date>2014-10-26T22:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data from Universal Forwarder into online sandbox instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186255#M37309</link>
      <description>&lt;P&gt;I'd say the question contains all the steps necessary, thanks Nick!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2014 17:00:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186255#M37309</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-27T17:00:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data from Universal Forwarder into online sandbox instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186256#M37310</link>
      <description>&lt;P&gt;You are welcome! Please try out the steps and let me know if they aren't working.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2014 17:18:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186256#M37310</guid>
      <dc:creator>Nicholas_Key</dc:creator>
      <dc:date>2014-10-27T17:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data from Universal Forwarder into online sandbox instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186257#M37311</link>
      <description>&lt;P&gt;Can't do that, US/Canada only &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Oct 2014 20:08:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186257#M37311</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-10-27T20:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data from Universal Forwarder into online sandbox instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186258#M37312</link>
      <description>&lt;P&gt;Since early December 2014 the steps to use a forwarder in the sandbox have changed.  To forward data to a sandbox you can use Universal Forwarder App available in Splunk Online Sandbox. The Universal Forwarder App includes the information and credentials necessary to download, install, and authorize you to forward data to Splunk Online Sandbox. After you sign in to Splunk Online Sandbox, choose Universal Forwarder from the Apps menu, and follow the Universal Forwarder app instructions.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2015 16:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186258#M37312</guid>
      <dc:creator>ryoung_splunk</dc:creator>
      <dc:date>2015-01-14T16:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to forward data from Universal Forwarder into online sandbox instance</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186259#M37313</link>
      <description>&lt;P&gt;Not true. Many places say "just download the universal forwarder and the app and install" does not work. Still errors out .&lt;/P&gt;

&lt;P&gt;01-27-2015 19:52:39.782 +1000 ERROR TcpOutputFd - Read error. An existing connection was forcibly closed by the remote host.&lt;BR /&gt;
01-27-2015 19:52:40.942 +1000 INFO  TcpOutputProc - Connected to idx=54.84.49.180:9997 using ACK.&lt;BR /&gt;
01-27-2015 19:52:47.265 +1000 INFO  TailingProcessor - Could not send data to output queue (parsingQueue), retrying...&lt;/P&gt;</description>
      <pubDate>Tue, 27 Jan 2015 09:54:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-forward-data-from-Universal-Forwarder-into-online-sandbox/m-p/186259#M37313</guid>
      <dc:creator>DelProfundo</dc:creator>
      <dc:date>2015-01-27T09:54:35Z</dc:date>
    </item>
  </channel>
</rss>

