<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250170#M48115</link>
    <description>&lt;P&gt;Try checking your universal forwarder installation against these instructions: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SplunkLight/6.5.0/GettingStarted/GettingdataintoSplunkLightusingWindows"&gt;http://docs.splunk.com/Documentation/SplunkLight/6.5.0/GettingStarted/GettingdataintoSplunkLightusingWindows&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Oct 2016 18:09:14 GMT</pubDate>
    <dc:creator>gneumann_splunk</dc:creator>
    <dc:date>2016-10-10T18:09:14Z</dc:date>
    <item>
      <title>After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250169#M48114</link>
      <description>&lt;P&gt;I installed the Universal Forwarder using the MSI, specified server info, but didn't check any boxes for wineventlog and such. I can see the PC checking in on the Splunk server, but it's not receiving any data. This is my ...\etc\system\local\inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = PBDC-LT-16

[WinEventLog:System]
interval=60
index=wineventlog
disabled=0

[WinEventLog:Security]
interval=60
index=wineventlog
disabled=0

[WinEventLog:Application]
interval=60
index=wineventlog
disabled=0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 10 Oct 2016 17:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250169#M48114</guid>
      <dc:creator>tmontney</dc:creator>
      <dc:date>2016-10-10T17:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250170#M48115</link>
      <description>&lt;P&gt;Try checking your universal forwarder installation against these instructions: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/SplunkLight/6.5.0/GettingStarted/GettingdataintoSplunkLightusingWindows"&gt;http://docs.splunk.com/Documentation/SplunkLight/6.5.0/GettingStarted/GettingdataintoSplunkLightusingWindows&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 18:09:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250170#M48115</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2016-10-10T18:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250171#M48116</link>
      <description>&lt;P&gt;Is your &lt;CODE&gt;outputs.conf&lt;/CODE&gt; pointing to your indexer? Did you restart the Splunk web service after making these changes?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 18:31:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250171#M48116</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-10-10T18:31:05Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250172#M48117</link>
      <description>&lt;P&gt;Very nice, I didn't realize this was an option. However, it's a bit light. The config files have far more options to configure, and I can't determine how to do that.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 18:41:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250172#M48117</guid>
      <dc:creator>tmontney</dc:creator>
      <dc:date>2016-10-10T18:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250173#M48118</link>
      <description>&lt;P&gt;Yep, outputs.conf is fine. The inputs.conf file I'm referencing here is on the forwarder, not the server. Why would I restart the server?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 18:47:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250173#M48118</guid>
      <dc:creator>tmontney</dc:creator>
      <dc:date>2016-10-10T18:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250174#M48119</link>
      <description>&lt;P&gt;Try the Splunk Enterprise Getting Data In manual, which has more information:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/Data/AboutWindowsdataandSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.0/Data/AboutWindowsdataandSplunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 18:51:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250174#M48119</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2016-10-10T18:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250175#M48120</link>
      <description>&lt;P&gt;More specific instructions for event log monitoring and universal forwarder config info using Windows: &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/Data/MonitorWindowseventlogdata"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.0/Data/MonitorWindowseventlogdata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 18:57:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250175#M48120</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2016-10-10T18:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250176#M48121</link>
      <description>&lt;P&gt;Again, I have followed that. I have changed /etc/system/local/inputs.conf to the config shown above, on the local forwarder. I restarted the Splunk Forwarder service, and did not see any change.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 19:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250176#M48121</guid>
      <dc:creator>tmontney</dc:creator>
      <dc:date>2016-10-10T19:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250177#M48122</link>
      <description>&lt;P&gt;Here's a similar situation on Answers that might help resolve your issue: &lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/98072/not-receiving-data-from-windows-forwarder.html"&gt;https://answers.splunk.com/answers/98072/not-receiving-data-from-windows-forwarder.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In particular "Have you opened the port on your Splunk indexer to receive data from the forwarder? I would try doing a tcpdump/netstat to see if data is leaving the Windows box and/or being received on the Splunk Indexer."&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 20:24:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250177#M48122</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2016-10-10T20:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250178#M48123</link>
      <description>&lt;P&gt;If I configure Splunk server to get the data, it works. I'm feeling it's just wrong config rather than ports or firewalls. I'll take a look though.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 21:10:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250178#M48123</guid>
      <dc:creator>tmontney</dc:creator>
      <dc:date>2016-10-10T21:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250179#M48124</link>
      <description>&lt;P&gt;My apology, it is working actually. I was basing it off the "Last Updated" section of the Search page. It was looking for the hostname rather than the hostname's FQDN (treating them as separate hosts).&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 21:20:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250179#M48124</guid>
      <dc:creator>tmontney</dc:creator>
      <dc:date>2016-10-10T21:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: After installing the Universal Forwarder using MSI, I am not receiving any data. How to edit my configuration?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250180#M48125</link>
      <description>&lt;P&gt;Great to know it's working! &lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 21:46:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/After-installing-the-Universal-Forwarder-using-MSI-I-am-not/m-p/250180#M48125</guid>
      <dc:creator>gneumann_splunk</dc:creator>
      <dc:date>2016-10-10T21:46:21Z</dc:date>
    </item>
  </channel>
</rss>

