<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to troubleshoot why my heavy forwarder is not receiving Windows event logs from the universal forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283829#M54274</link>
    <description>&lt;P&gt;I want to send "wineventlog:security " logs to &lt;STRONG&gt;Heavy forwarder(KIWISERVER)&lt;/STRONG&gt; and below are the configuration files that I have created on the &lt;STRONG&gt;Universal forwarder&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;inputs.conf:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Security]
disabled = 0
index = activedirectory
sourcetype=adlog_003
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;outputs.conf:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = xxx.xx.xxx.xx:9997

[tcpout-server://xxx.xx.xxx.xx9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When i see the "Splunkd" log it shows  "&lt;STRONG&gt;Connected to idx=xxx.xx.xxx.xx:9997"&lt;/STRONG&gt; but i'm unable to see the events in splunk search &lt;EM&gt;index=active&lt;/EM&gt;*&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;sample **splunkd&lt;/STRONG&gt; log file :**&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12-17-2016 01:09:30.162 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\license_usage_summary.log'.
12-17-2016 01:09:30.162 -0500 INFO  WatchedFile - Will begin reading at offset=424312 for file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\metrics.log'.
12-17-2016 01:09:30.178 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\remote_searches.log'.
12-17-2016 01:09:30.178 -0500 INFO  WatchedFile - Will begin reading at offset=854 for file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\conf.log'.
12-17-2016 01:09:30.287 -0500 INFO  TcpOutputProc - Connected to idx=xxx.xx.xxx.xx:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please let me know what mistake I have done.....&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="noresults"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2252iCDB8089D71634957/image-size/large?v=v2&amp;amp;px=999" role="button" title="noresults" alt="noresults" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 17 Dec 2016 06:34:28 GMT</pubDate>
    <dc:creator>chanamoluk</dc:creator>
    <dc:date>2016-12-17T06:34:28Z</dc:date>
    <item>
      <title>How to troubleshoot why my heavy forwarder is not receiving Windows event logs from the universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283829#M54274</link>
      <description>&lt;P&gt;I want to send "wineventlog:security " logs to &lt;STRONG&gt;Heavy forwarder(KIWISERVER)&lt;/STRONG&gt; and below are the configuration files that I have created on the &lt;STRONG&gt;Universal forwarder&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;inputs.conf:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[WinEventLog://Security]
disabled = 0
index = activedirectory
sourcetype=adlog_003
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;outputs.conf:&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = xxx.xx.xxx.xx:9997

[tcpout-server://xxx.xx.xxx.xx9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When i see the "Splunkd" log it shows  "&lt;STRONG&gt;Connected to idx=xxx.xx.xxx.xx:9997"&lt;/STRONG&gt; but i'm unable to see the events in splunk search &lt;EM&gt;index=active&lt;/EM&gt;*&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;sample **splunkd&lt;/STRONG&gt; log file :**&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;12-17-2016 01:09:30.162 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\license_usage_summary.log'.
12-17-2016 01:09:30.162 -0500 INFO  WatchedFile - Will begin reading at offset=424312 for file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\metrics.log'.
12-17-2016 01:09:30.178 -0500 INFO  WatchedFile - File too small to check seekcrc, probably truncated.  Will re-read entire file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\remote_searches.log'.
12-17-2016 01:09:30.178 -0500 INFO  WatchedFile - Will begin reading at offset=854 for file='C:\Program Files\SplunkUniversalForwarder\var\log\splunk\conf.log'.
12-17-2016 01:09:30.287 -0500 INFO  TcpOutputProc - Connected to idx=xxx.xx.xxx.xx:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Please let me know what mistake I have done.....&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="noresults"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/2252iCDB8089D71634957/image-size/large?v=v2&amp;amp;px=999" role="button" title="noresults" alt="noresults" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Dec 2016 06:34:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283829#M54274</guid>
      <dc:creator>chanamoluk</dc:creator>
      <dc:date>2016-12-17T06:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why my heavy forwarder is not receiving Windows event logs from the universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283830#M54275</link>
      <description>&lt;P&gt;( I don't know why I can't add comment) &lt;/P&gt;

&lt;P&gt;I'd like to suggest Just to monitor some file and send it to your index in order to identify the root cause.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Dec 2016 11:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283830#M54275</guid>
      <dc:creator>tkomatsubara_sp</dc:creator>
      <dc:date>2016-12-17T11:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why my heavy forwarder is not receiving Windows event logs from the universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283831#M54276</link>
      <description>&lt;P&gt;Are you searching from your searchhead or from the heavyforwarder? &lt;/P&gt;

&lt;P&gt;can you see internal logs from the forwarder?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=&amp;lt;yourUF&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;check metrics.log for your sourcetype. (sidenote: i don't think you need to be setting the sourcetype like that for a windows input, are you using any windows apps or TAs?)&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal host=&amp;lt;yourUF&amp;gt; source=*metrics.log 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;check inputstatus on the forwarder using the &lt;CODE&gt;splunk list inputstatus&lt;/CODE&gt; command (depends on uf version - 6.3 or 6.4+ i think?)&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/AbouttheCLI"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.1/Admin/AbouttheCLI&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Dec 2016 14:46:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283831#M54276</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2016-12-17T14:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why my heavy forwarder is not receiving Windows event logs from the universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283832#M54277</link>
      <description>&lt;P&gt;i'm searching on "Heavy forwarder" and i cannot see internal logs as well.&lt;/P&gt;

&lt;P&gt;i think this is a firewall issue? &lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 14:51:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283832#M54277</guid>
      <dc:creator>chanamoluk</dc:creator>
      <dc:date>2016-12-19T14:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why my heavy forwarder is not receiving Windows event logs from the universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283833#M54278</link>
      <description>&lt;P&gt;I think the issue is you are forwarding your logs to the indexers, and the HF is not configured to search the data on the indexers. You need to search from the indexers themselves, or from a Search Head that has access to the data on the indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Dec 2016 19:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283833#M54278</guid>
      <dc:creator>coltwanger</dc:creator>
      <dc:date>2016-12-19T19:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to troubleshoot why my heavy forwarder is not receiving Windows event logs from the universal forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283834#M54279</link>
      <description>&lt;P&gt;Yep, like coltwanger said,&lt;/P&gt;

&lt;P&gt;if your HF is not set up for distributed search, you wont see the logs from there!&lt;/P&gt;

&lt;P&gt;Check from the search head, ideally.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Dec 2016 00:36:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-troubleshoot-why-my-heavy-forwarder-is-not-receiving/m-p/283834#M54279</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2016-12-20T00:36:25Z</dc:date>
    </item>
  </channel>
</rss>

