<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279057#M53404</link>
    <description>&lt;P&gt;You don't need to configure a receiving port. Did you define inputs? See &lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.4.0/Forwarder/HowtoforwarddatatoSplunkCloud"&gt;How to forward data to Splunk Cloud&lt;/A&gt; in the &lt;EM&gt;Forwarder Manual&lt;/EM&gt;.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Apr 2016 23:04:25 GMT</pubDate>
    <dc:creator>ChrisG</dc:creator>
    <dc:date>2016-04-07T23:04:25Z</dc:date>
    <item>
      <title>How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279055#M53402</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I recently started using the Splunk Cloud free trial. I installed a universal forwarder locally and authorized it with the credential downloaded from Splunk Cloud.&lt;BR /&gt;
I don't see any option in the Splunk Cloud UI to configure a receiving port. How do I make the forwarder send data to Splunk Cloud?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Saravana&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Update with additional information:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;These are the steps I have done...&lt;/P&gt;

&lt;P&gt;Universal Forwarder&lt;BR /&gt;
-I got my Splunk cloud free trial login&lt;BR /&gt;
-Downloaded the universal forwarder app&lt;BR /&gt;
-Installed the app by using the credential downloaded as spl file.&lt;BR /&gt;
-I added a particular directory to monitor.&lt;/P&gt;

&lt;P&gt;Using Splunk Enterprise Forwarder&lt;BR /&gt;
-Configured the Splunk Cloud instance and port in forwarder section of my Splunk Enterprise.&lt;BR /&gt;
-Not able to see receiving port section in Splunk Cloud instance&lt;/P&gt;

&lt;P&gt;When I do list monitor, I get the directory in list of monitored directories. but data is not available in search of Splunk Cloud&lt;/P&gt;

&lt;P&gt;Please let me know as to where the problem might be.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 22:23:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279055#M53402</guid>
      <dc:creator>sakarunanitk</dc:creator>
      <dc:date>2016-04-07T22:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279056#M53403</link>
      <description>&lt;P&gt;I have the same issue.&lt;BR /&gt;
On my client I ran:&lt;BR /&gt;
SPLUNK.exe install app splunkclouduf.spl -auth&lt;/P&gt;

&lt;P&gt;I get: Login Failed&lt;/P&gt;

&lt;P&gt;Do I use a different name and password than what I use to login into my Splunk Trial/Console on the web?&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 22:55:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279056#M53403</guid>
      <dc:creator>gearmesh</dc:creator>
      <dc:date>2016-04-07T22:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279057#M53404</link>
      <description>&lt;P&gt;You don't need to configure a receiving port. Did you define inputs? See &lt;A href="http://docs.splunk.com/Documentation/Forwarder/6.4.0/Forwarder/HowtoforwarddatatoSplunkCloud"&gt;How to forward data to Splunk Cloud&lt;/A&gt; in the &lt;EM&gt;Forwarder Manual&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 23:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279057#M53404</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-04-07T23:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279058#M53405</link>
      <description>&lt;P&gt;I found my answer.&lt;/P&gt;

&lt;P&gt;The default pre-populated url below would not accept the default username and password&lt;BR /&gt;
&lt;STRONG&gt;&lt;A href="http://computername:8000/en-US/account/login"&gt;http://computername:8000/en-US/account/login&lt;/A&gt;&lt;/STRONG&gt;&lt;BR /&gt;
change it to this:&lt;BR /&gt;
&lt;STRONG&gt;&lt;A href="http://localhost:8000"&gt;http://localhost:8000&lt;/A&gt;&lt;/STRONG&gt;&lt;BR /&gt;
and the defaults username and password work and allow you to change the password.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 17:36:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279058#M53405</guid>
      <dc:creator>gearmesh</dc:creator>
      <dc:date>2016-04-08T17:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279059#M53406</link>
      <description>&lt;P&gt;Where did you change this url ? Is it part of universal forwarder configuration somewhere?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 17:52:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279059#M53406</guid>
      <dc:creator>sakarunanitk</dc:creator>
      <dc:date>2016-04-08T17:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279060#M53407</link>
      <description>&lt;P&gt;I downvoted this post because when i do list monitor  i get the directory in list of monitored directories. but data is not available in search of splunk cloud. i have installed the universal forwarder with the spl file downloaded from my splunk cloud instance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 18:16:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279060#M53407</guid>
      <dc:creator>sakarunanitk</dc:creator>
      <dc:date>2016-04-11T18:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279061#M53408</link>
      <description>&lt;P&gt;Can you give an example of your inputs.conf file? Did you add the necessary stanzas as described in &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.0/Data/Monitorfilesanddirectorieswithinputs.conf"&gt;Monitor files and directories with inputs.conf&lt;/A&gt; in the &lt;EM&gt;Getting Data In&lt;/EM&gt; manual?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 19:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279061#M53408</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2016-04-11T19:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279062#M53409</link>
      <description>&lt;P&gt;This is the input.conf file in C:\Program Files\Splunk\etc\system\local&lt;/P&gt;

&lt;P&gt;[default]&lt;BR /&gt;
host = SAKARUNA-WS&lt;/P&gt;

&lt;P&gt;[monitor://$SPLUNK_HOME\etc\splunk.version]&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;[monitor://C:\SplunkDir]&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;c:\SplunkDir is the directory i want to monitor&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Saravana&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 20:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279062#M53409</guid>
      <dc:creator>sakarunanitk</dc:creator>
      <dc:date>2016-04-11T20:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279063#M53410</link>
      <description>&lt;P&gt;That is the url that opens after completing the forwarder (6.1) installation.&lt;BR /&gt;
It also can be entered in a browser once the forwarder is installed.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2016 00:08:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279063#M53410</guid>
      <dc:creator>gearmesh</dc:creator>
      <dc:date>2016-04-12T00:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279064#M53411</link>
      <description>&lt;P&gt;Any thoughts on this Chris.?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 17:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279064#M53411</guid>
      <dc:creator>sakarunanitk</dc:creator>
      <dc:date>2016-04-13T17:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279065#M53412</link>
      <description>&lt;UL&gt;
&lt;LI&gt;first of all, there is no UI in an universal forwarder, so if you see an UI, this is a full instance, or a heavy forwarder.&lt;/LI&gt;
&lt;LI&gt;you do not need to open ports or inputs on the cloud instsances, they are already listening, just setup your forwarder&lt;/LI&gt;
&lt;/UL&gt;

&lt;HR /&gt;

&lt;P&gt;1 - When you install the forwarder package&lt;BR /&gt;
download from splunk.com or from the splunkcloud UI, Usually the Universal Forwarder is fine, in some special cases, you may need the full splunk install (to use it as an Heavy forwarder)&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;on linux it's simple. untar, rpm, deb ....&lt;/LI&gt;
&lt;LI&gt;on windows, there is a wizard, please &lt;STRONG&gt;do not use the wizards pages to setup the forwarding to cloud&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;2 - once the forwarder is installed, the user for the CLI is "admin" password "changeme"&lt;BR /&gt;
Then you need to install the cloud app package (download from your splunkcloud instance, un the app UF)&lt;BR /&gt;
the package is a *.spl&lt;/P&gt;

&lt;P&gt;you can install it on the command line with &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#on linux
   cd /opt/splunkforwarder/bin
   ./splunk install app /path/to/my/&amp;lt;mycloudforwarderpackage.spl&amp;gt;



 #on windows, 
    cd C:\Program files\splunkforwarder\bin
    splunk.exe install app path\to\my\&amp;lt;mycloudforwarderpackage.spl&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If it fails, or if you want to install the app manually (or tune , or prepare for a deployment server)&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;rename the .spl to a .tar.gz&lt;/LI&gt;
&lt;LI&gt;untar the file, to a folder&lt;/LI&gt;
&lt;LI&gt;copy the app folder to your /opt/splunkforwarder/etc/apps/ or C:\Program files\splunkforwarder\etc\apps (or on your deployment server and push)&lt;/LI&gt;
&lt;LI&gt;restart the forwarder to apply&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;3 - To validate, read your forwarder  /opt/splunkforwarder/var/log/splunk/splunkd.log&lt;BR /&gt;
and test from the cloud instance that you can see the internal logs&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;   index=_internal host=&amp;lt;myforwarder&amp;gt; *
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;4- next step, setup your inputs, you can read the classic splunk inputs manuals, or use apps.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 18:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279065#M53412</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2016-04-13T18:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279066#M53413</link>
      <description>&lt;P&gt;Thanks a ton for a quick and elaborate reply. Really helps.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 18:34:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279066#M53413</guid>
      <dc:creator>sakarunanitk</dc:creator>
      <dc:date>2016-04-13T18:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279067#M53414</link>
      <description>&lt;P&gt;Hi @Yannk,&lt;/P&gt;

&lt;P&gt;Had a quick question.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Below is my splunkd.log&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - TailWatcher initializing...
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Parsing configuration stanza: batch://$SPLUNK_HOME/var/spool/splunk.
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Parsing configuration stanza: batch://$SPLUNK_HOME/var/spool/splunk/...stash_new.
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/etc/splunk.version.
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk.
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk/metrics.log.
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Parsing configuration stanza: monitor://$SPLUNK_HOME/var/log/splunk/splunkd.log.
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Parsing configuration stanza: monitor:///root/data.
04-13-2016 11:54:45.568 -0700 INFO  TailReader - State transitioning from 1 to 0 (initOrResume).
04-13-2016 11:54:45.568 -0700 INFO  TailReader - State transitioning from 1 to 0 (initOrResume).
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Adding watch on path: /opt/splunkforwarder/etc/splunk.version.
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Adding watch on path: /opt/splunkforwarder/var/log/splunk.
04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Adding watch on path: /opt/splunkforwarder/var/spool/splunk.
**04-13-2016 11:54:45.568 -0700 INFO  TailingProcessor - Adding watch on path: /root/data**.
04-13-2016 11:54:45.568 -0700 INFO  TailReader - Registering metrics callback for: tailreader0
04-13-2016 11:54:45.568 -0700 INFO  TailReader - Starting tailreader0 thread
04-13-2016 11:54:45.569 -0700 INFO  TailReader - Registering metrics callback for: batchreader0
04-13-2016 11:54:45.570 -0700 INFO  TailReader - Starting batchreader0 thread
04-13-2016 11:54:45.571 -0700 INFO  loader - Limiting REST HTTP server to 1365 sockets
04-13-2016 11:54:45.571 -0700 INFO  loader - Limiting REST HTTP server to 1365 threads
04-13-2016 11:54:45.571 -0700 WARN  X509Verify - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) should not be used, as it is issued by Splunk's own default Certificate Authority (CA). This puts your Splunk instance at very high-risk of the MITM attack. Either commercial-CA-signed or self-CA-signed certificates must be used; see: 
04-13-2016 11:54:45.597 -0700 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='/opt/splunkforwarder/var/log/splunk/searchhistory.log'.
04-13-2016 11:54:45.659 -0700 ERROR TcpOutputFd - Read error. Connection reset by peer
04-13-2016 11:54:45.661 -0700 INFO  WatchedFile - Will begin reading at offset=2558565 for file='/opt/splunkforwarder/var/log/splunk/metrics.log'.
**04-13-2016 11:54:50.665 -0700 INFO  TailReader - Could not send data to output queue (parsingQueue), retrying...
04-13-2016 11:55:15.392 -0700 WARN  UserManagerPro - Can't find [distributedSearch] stanza in distsearch.conf, using default authtoken HTTP timeouts
04-13-2016 11:55:15.528 -0700 ERROR TcpOutputFd - Read error. Connection reset by peer
04-13-2016 11:55:45.527 -0700 ERROR TcpOutputFd - Read error. Connection reset by peer**
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I see that the folder is monitored, but connection is getting reset. I checked out certain other answers and set &lt;CODE&gt;sendCookedData = true&lt;/CODE&gt;. Even that didn't work. Is there something else I am missing?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Saravana &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 19:04:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279067#M53414</guid>
      <dc:creator>sakarunanitk</dc:creator>
      <dc:date>2016-04-13T19:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: How do I configure a universal forwarder to send data to the Splunk Cloud free trial?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279068#M53415</link>
      <description>&lt;P&gt;I am able to telnet to the splunk host and port 9997. &lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 20:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-configure-a-universal-forwarder-to-send-data-to-the/m-p/279068#M53415</guid>
      <dc:creator>sakarunanitk</dc:creator>
      <dc:date>2016-04-13T20:39:49Z</dc:date>
    </item>
  </channel>
</rss>

