<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I unable to forward logs from a Linux machine to Windows using Splunk 6.3? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206291#M40716</link>
    <description>&lt;P&gt;Hi CREVITCH,&lt;/P&gt;

&lt;P&gt;run this search &lt;CODE&gt;| tstats count WHERE index=* sourcetype=* by index, sourcetype, host&lt;/CODE&gt; to see if the host is listed, if so run a search over all time for the index listed in above search result:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=&amp;lt;from above&amp;gt; earliest=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;check &lt;CODE&gt;splunkd.log&lt;/CODE&gt;or &lt;CODE&gt;index=_internal&lt;/CODE&gt; for errors related to this host/input maybe date errors and the timestamp is not recognised? Hint &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/Configuretimestamprecognition"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/Configuretimestamprecognition&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Mon, 26 Oct 2015 22:41:12 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2015-10-26T22:41:12Z</dc:date>
    <item>
      <title>Why am I unable to forward logs from a Linux machine to Windows using Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206290#M40715</link>
      <description>&lt;P&gt;I am new to Splunk and downloaded Splunk free to several machines, Linux and Windows.  All machines are on the same subnet.  I have been successful at forwarding logs from Windows to Linux, and from Windows to Windows, but I cannot seem to see the Linux logs on the Windows Splunk. I see the TCP handshake and the log text, but Splunk never shows the machine name or the logs in the data summary.&lt;/P&gt;

&lt;P&gt;Using Splunk 6.3.0 on CentOS 6.6.  The logging capability seems to work fine on the Linux machine when viewed locally.  The Windows machines are both using Splunk 6.3.0 as well.&lt;/P&gt;

&lt;P&gt;Many Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 21:49:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206290#M40715</guid>
      <dc:creator>CREVITCH</dc:creator>
      <dc:date>2015-10-26T21:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to forward logs from a Linux machine to Windows using Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206291#M40716</link>
      <description>&lt;P&gt;Hi CREVITCH,&lt;/P&gt;

&lt;P&gt;run this search &lt;CODE&gt;| tstats count WHERE index=* sourcetype=* by index, sourcetype, host&lt;/CODE&gt; to see if the host is listed, if so run a search over all time for the index listed in above search result:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=&amp;lt;from above&amp;gt; earliest=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;check &lt;CODE&gt;splunkd.log&lt;/CODE&gt;or &lt;CODE&gt;index=_internal&lt;/CODE&gt; for errors related to this host/input maybe date errors and the timestamp is not recognised? Hint &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/Configuretimestamprecognition"&gt;http://docs.splunk.com/Documentation/Splunk/6.3.0/Data/Configuretimestamprecognition&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 22:41:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206291#M40716</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2015-10-26T22:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to forward logs from a Linux machine to Windows using Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206292#M40717</link>
      <description>&lt;P&gt;thank you. I ran the search and the source(forwarding) host (linux box) did not appear.  I still see my windows desktop (receiver) handshaking with the source on wireshark.  Any other things I can try?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 14:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206292#M40717</guid>
      <dc:creator>CREVITCH</dc:creator>
      <dc:date>2015-10-27T14:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I unable to forward logs from a Linux machine to Windows using Splunk 6.3?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206293#M40718</link>
      <description>&lt;P&gt;I just added the index the linux server was creating (os) to the windows splunk and it is now showing up.  Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 14:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-unable-to-forward-logs-from-a-Linux-machine-to-Windows/m-p/206293#M40718</guid>
      <dc:creator>CREVITCH</dc:creator>
      <dc:date>2015-10-27T14:18:20Z</dc:date>
    </item>
  </channel>
</rss>

