<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After setting up a universal forwarder and receiver on Windows, why am I getting &amp;quot;Error in 'DispatchProcess': Failed to write the info file to C:\Program Files\Splunk\var\run\splunk\dispatch\[lots of letters and numbers]\info.csv&amp;quot;? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/After-setting-up-a-universal-forwarder-and-receiver-on-Windows/m-p/237701#M46170</link>
    <description>&lt;P&gt;Are you sure you installed the Splunk Universal Forwarder and not a full Splunk installation? I would expect the directory to be &lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder....&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;In regards to your error, you might have some old erroneous results stored in the dispatch directory. You can manually clear out the "[lots of letters and numbers]" directory and restart Splunk and this should resolve the issue.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Nov 2015 22:53:47 GMT</pubDate>
    <dc:creator>nbjoshi_splunk</dc:creator>
    <dc:date>2015-11-17T22:53:47Z</dc:date>
    <item>
      <title>After setting up a universal forwarder and receiver on Windows, why am I getting "Error in 'DispatchProcess': Failed to write the info file to C:\Program Files\Splunk\var\run\splunk\dispatch\[lots of letters and numbers]\info.csv"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-setting-up-a-universal-forwarder-and-receiver-on-Windows/m-p/237700#M46169</link>
      <description>&lt;P&gt;I've set up a universal forwarder on a remote webserver using local system account (Win2008R2 64bit).&lt;/P&gt;

&lt;P&gt;I have enabled receiving on the receiver which is using a domain account (Win7 Pro 64bit). It asked to restart Splunk which I did.&lt;/P&gt;

&lt;P&gt;The dashboard is now showing:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Error in 'DispatchProcess': Failed to write the info file to C:\Program Files\Splunk\var\run\splunk\dispatch\[lots of letters and numbers]\info.csv
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 17 Nov 2015 15:39:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-setting-up-a-universal-forwarder-and-receiver-on-Windows/m-p/237700#M46169</guid>
      <dc:creator>mr_dombat</dc:creator>
      <dc:date>2015-11-17T15:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: After setting up a universal forwarder and receiver on Windows, why am I getting "Error in 'DispatchProcess': Failed to write the info file to C:\Program Files\Splunk\var\run\splunk\dispatch\[lots of letters and numbers]\info.csv"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-setting-up-a-universal-forwarder-and-receiver-on-Windows/m-p/237701#M46170</link>
      <description>&lt;P&gt;Are you sure you installed the Splunk Universal Forwarder and not a full Splunk installation? I would expect the directory to be &lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder....&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;In regards to your error, you might have some old erroneous results stored in the dispatch directory. You can manually clear out the "[lots of letters and numbers]" directory and restart Splunk and this should resolve the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2015 22:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-setting-up-a-universal-forwarder-and-receiver-on-Windows/m-p/237701#M46170</guid>
      <dc:creator>nbjoshi_splunk</dc:creator>
      <dc:date>2015-11-17T22:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: After setting up a universal forwarder and receiver on Windows, why am I getting "Error in 'DispatchProcess': Failed to write the info file to C:\Program Files\Splunk\var\run\splunk\dispatch\[lots of letters and numbers]\info.csv"?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-setting-up-a-universal-forwarder-and-receiver-on-Windows/m-p/237702#M46171</link>
      <description>&lt;P&gt;The error message was manifesting itself in the full splunk.&lt;/P&gt;

&lt;P&gt;On the indexer/receiver I deleted the files as requested it made no difference.&lt;/P&gt;

&lt;P&gt;I changed the two services to run as interactive desktop enabled LocalService and restarted splunk, same messages.&lt;/P&gt;

&lt;P&gt;I checked permissions on the folder(s) and added my domain and localsevice both as Full control, restarted, same messages.&lt;/P&gt;

&lt;P&gt;I uninstalled Splunk, cleaned the registry using CCLeaner, rebooted, reinstalled using Local account (default setting) and it seems OK now.&lt;/P&gt;

&lt;P&gt;Not getting anything from my forwarders still  but that is a different question.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 10:15:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-setting-up-a-universal-forwarder-and-receiver-on-Windows/m-p/237702#M46171</guid>
      <dc:creator>mr_dombat</dc:creator>
      <dc:date>2015-11-18T10:15:32Z</dc:date>
    </item>
  </channel>
</rss>

