<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to troubleshoot the Universal Forwarder when it is not sending events to the indexer? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202094#M39992</link>
    <description>&lt;P&gt;Hi, Thanks for the quick reply. &lt;/P&gt;

&lt;P&gt;I dont know if the data is being forwarded correctly. I am looking for guidance to confirm that. &lt;/P&gt;

&lt;P&gt;regards,&lt;BR /&gt;
Sarthak&lt;/P&gt;</description>
    <pubDate>Mon, 19 Dec 2016 16:48:15 GMT</pubDate>
    <dc:creator>sarthakb</dc:creator>
    <dc:date>2016-12-19T16:48:15Z</dc:date>
    <item>
      <title>How to troubleshoot the Universal Forwarder when it is not sending events to the indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202092#M39990</link>
      <description>&lt;P&gt;We have a existing infrastructure of Splunk where events are passed from multiple Linux boxes to Splunk indexers.&lt;/P&gt;

&lt;P&gt;We recently have installed Splunk &lt;STRONG&gt;forwarder&lt;/STRONG&gt; in a &lt;STRONG&gt;Windows&lt;/STRONG&gt; box. When we search in Splunk using that host name, we don't see the events. &lt;/P&gt;

&lt;P&gt;We have checked the logs with the following observation&lt;BR /&gt;
- It is picking up new monitor config.&lt;BR /&gt;
- No error is reported in Splunkd.log&lt;/P&gt;

&lt;P&gt;Can you please share the &lt;STRONG&gt;troubleshooting&lt;/STRONG&gt; &lt;STRONG&gt;steps&lt;/STRONG&gt; for the forwarder? Can &lt;STRONG&gt;forwarder log files&lt;/STRONG&gt; help us pin point - &lt;STRONG&gt;if forwarder at all sending the events to Indexer?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 16:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202092#M39990</guid>
      <dc:creator>sarthakb</dc:creator>
      <dc:date>2016-12-19T16:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot the Universal Forwarder when it is not sending events to the indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202093#M39991</link>
      <description>&lt;P&gt;So the data is being forwarded correctly to your indexer(s) but you cannot find the host when searching?&lt;/P&gt;

&lt;P&gt;Can you check the &lt;CODE&gt;outputs.conf&lt;/CODE&gt; on the forwarder to verify you have the correct hostname there?&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;C:\SPLUNK_HOME\etc\system\local\outputs.conf&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 16:43:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202093#M39991</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-12-19T16:43:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot the Universal Forwarder when it is not sending events to the indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202094#M39992</link>
      <description>&lt;P&gt;Hi, Thanks for the quick reply. &lt;/P&gt;

&lt;P&gt;I dont know if the data is being forwarded correctly. I am looking for guidance to confirm that. &lt;/P&gt;

&lt;P&gt;regards,&lt;BR /&gt;
Sarthak&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 16:48:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202094#M39992</guid>
      <dc:creator>sarthakb</dc:creator>
      <dc:date>2016-12-19T16:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot the Universal Forwarder when it is not sending events to the indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202095#M39993</link>
      <description>&lt;P&gt;Good place to start at &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Troubleshooting/Cantfinddata"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 16:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202095#M39993</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-12-19T16:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot the Universal Forwarder when it is not sending events to the indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202096#M39994</link>
      <description>&lt;P&gt;Along the lines of skoelpin's comment, it sounds like there may be an issue sending from the UF to the indexer. Can you see in the splunkd.log on the UF that the UF is successfully connecting to the indexer?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 17:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202096#M39994</guid>
      <dc:creator>chrishartsock</dc:creator>
      <dc:date>2016-12-19T17:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot the Universal Forwarder when it is not sending events to the indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202097#M39995</link>
      <description>&lt;P&gt;@ sarthakb  refer to below thread...you can refer to my answer there to get some tips and also others answers as well&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/5590/could-not-send-data-to-the-output-queue.html#answer-466859"&gt;https://answers.splunk.com/answers/5590/could-not-send-data-to-the-output-queue.html#answer-466859&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;As @chrishartsoc mentioned...your starting point is checking splunkd and metrics log on the forwarder.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 18:31:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202097#M39995</guid>
      <dc:creator>nekbote</dc:creator>
      <dc:date>2016-12-19T18:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot the Universal Forwarder when it is not sending events to the indexer?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202098#M39996</link>
      <description>&lt;P&gt;Interesting Observation - The forwarder is able to send data to indexer in each line does not starts with a date time. &lt;/P&gt;

&lt;P&gt;e.g &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12/13/2016 12:45:77.907 -0500 Some content 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The above line fails&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12/13/2016 Some content 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Above line works &lt;/P&gt;

&lt;P&gt;Seems like forwarder is trying to parse date time. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Is there a way to forcefully tell forwarder not to parse datetime?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 20:51:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-the-Universal-Forwarder-when-it-is-not/m-p/202098#M39996</guid>
      <dc:creator>sarthakb</dc:creator>
      <dc:date>2016-12-19T20:51:44Z</dc:date>
    </item>
  </channel>
</rss>

