<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: getting errors from my splunk logs on monitor PC in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220588#M43335</link>
    <description>&lt;P&gt;do you mean the location of the input and output.conf? if so i edit them from here&lt;/P&gt;

&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\etc\system\local&lt;/P&gt;</description>
    <pubDate>Tue, 04 Oct 2016 17:01:27 GMT</pubDate>
    <dc:creator>rsingh</dc:creator>
    <dc:date>2016-10-04T17:01:27Z</dc:date>
    <item>
      <title>getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220578#M43325</link>
      <description>&lt;P&gt;Error 1 - ERROR TcpOutputFd - Read error. An established connection was aborted by the software in your host machine.&lt;/P&gt;

&lt;P&gt;Error 2 - ERROR ExecProcessor - message from ""C:\Program Files\SplunkUniversalForwarder\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::enumEvtLogChannels: Failed to enumerate event log channels: '(1722)'.&lt;/P&gt;

&lt;P&gt;Error 3 -  WARN  TcpOutputProc - Forwarding to indexer group default-autolb-group blocked for 400 seconds.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;this is my input.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = MYSERVER4&lt;/P&gt;

&lt;P&gt;[script://$SPLUNK_HOME\bin\scripts\splunk-wmi.path]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;[splunktcp://9996]&lt;BR /&gt;
Connection_host = none&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;output.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = mysplunk.domain.com:9996&lt;/P&gt;

&lt;P&gt;[tcpout-server://mysplunk.domain.com:9996]&lt;/P&gt;

&lt;P&gt;please help. i can telnet into port 9996 and my splunk server = Forwarding and Receiving &amp;gt; Receiving on port 9996&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 20:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220578#M43325</guid>
      <dc:creator>rsingh</dc:creator>
      <dc:date>2016-10-03T20:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220579#M43326</link>
      <description>&lt;P&gt;Are you running the Splunk service as a user or local system?  When you disable the service and run the following command 'netstat -ano | findstr 9996' is there a record there?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 20:20:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220579#M43326</guid>
      <dc:creator>dperre_splunk</dc:creator>
      <dc:date>2016-10-03T20:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220580#M43327</link>
      <description>&lt;P&gt;Splunk service is running as a local user, i stoped the service and run 'netstat -ano | findstr 9996&lt;/P&gt;

&lt;P&gt;where should i look for the record?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 20:23:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220580#M43327</guid>
      <dc:creator>rsingh</dc:creator>
      <dc:date>2016-10-03T20:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220581#M43328</link>
      <description>&lt;P&gt;Change the service to run as local system.  Unless you are pulling logs remotely from that machine I don't see any need to run as a user account.  &lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 20:25:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220581#M43328</guid>
      <dc:creator>dperre_splunk</dc:creator>
      <dc:date>2016-10-03T20:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220582#M43329</link>
      <description>&lt;P&gt;i do have a Red Hat splunk server&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 20:29:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220582#M43329</guid>
      <dc:creator>rsingh</dc:creator>
      <dc:date>2016-10-03T20:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220583#M43330</link>
      <description>&lt;P&gt;Sorry, I was talking about the universal forwarder.  Make the actions I mentioned above on the host that is running the universal forwarder should be a windows machine.  So let me know what user is running the service and what the results of the netstat command are.&lt;/P&gt;

&lt;P&gt;Also,  Add disabled = 0 under splunktcp:9996 on your indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 20:34:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220583#M43330</guid>
      <dc:creator>dperre_splunk</dc:creator>
      <dc:date>2016-10-03T20:34:06Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220584#M43331</link>
      <description>&lt;P&gt;This should NOT be part of the inputs.conf on your forwarder:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunktcp://9996]
Connection_host = none
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The forwarder is blocking itself. &lt;/P&gt;

&lt;P&gt;If I misunderstood and both of these files are on the indexer: then the indexer is forwarding to itself, and again, it will be blocking.&lt;/P&gt;

&lt;P&gt;I see these types of messages often when I make similar typos...&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 02:36:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220584#M43331</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-10-04T02:36:18Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220585#M43332</link>
      <description>&lt;P&gt;ok so the universal forwarder is running as Local System, i ran a netstat command - where do i find the results? after i ran the command nothing happens&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 12:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220585#M43332</guid>
      <dc:creator>rsingh</dc:creator>
      <dc:date>2016-10-04T12:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220586#M43333</link>
      <description>&lt;P&gt;i removed the  [splunktcp://9996] Connection_host = none but the errors are still occuring&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 12:56:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220586#M43333</guid>
      <dc:creator>rsingh</dc:creator>
      <dc:date>2016-10-04T12:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220587#M43334</link>
      <description>&lt;P&gt;Hi rsingh,&lt;BR /&gt;
Can you edit your original post and let us know where you got each config from please. Ie was inputs.conf from indexer or universal forwarder and the same for outputs.conf&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 16:58:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220587#M43334</guid>
      <dc:creator>dperre_splunk</dc:creator>
      <dc:date>2016-10-04T16:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: getting errors from my splunk logs on monitor PC</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220588#M43335</link>
      <description>&lt;P&gt;do you mean the location of the input and output.conf? if so i edit them from here&lt;/P&gt;

&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\etc\system\local&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2016 17:01:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/getting-errors-from-my-splunk-logs-on-monitor-PC/m-p/220588#M43335</guid>
      <dc:creator>rsingh</dc:creator>
      <dc:date>2016-10-04T17:01:27Z</dc:date>
    </item>
  </channel>
</rss>

