<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trouble getting the Windows universal forwarder to forward data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294092#M55895</link>
    <description>&lt;P&gt;Hello all, I can't seem to get the windows universal forwarder to forward data.&lt;BR /&gt;
- Splunk indexer (7.x.x) is on CentOS7, 8089 and 9997 open on firewall&lt;BR /&gt;
- Latest Splunk forwarder installed on windows 10&lt;BR /&gt;
- Did not go into customize on windows installer GUI, but did put the win event stanza from documentation into the forwarder inputs.conf (system local).&lt;BR /&gt;
- opened 9997 data input in webui&lt;BR /&gt;
- Turned off windows firewall for troubleshooting.&lt;BR /&gt;
- Downloaded various windows apps/add-ons to splunk indexer thinking it was a deployment thing&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;</description>
    <pubDate>Wed, 22 Nov 2017 22:05:38 GMT</pubDate>
    <dc:creator>ShaunBaker</dc:creator>
    <dc:date>2017-11-22T22:05:38Z</dc:date>
    <item>
      <title>Trouble getting the Windows universal forwarder to forward data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294092#M55895</link>
      <description>&lt;P&gt;Hello all, I can't seem to get the windows universal forwarder to forward data.&lt;BR /&gt;
- Splunk indexer (7.x.x) is on CentOS7, 8089 and 9997 open on firewall&lt;BR /&gt;
- Latest Splunk forwarder installed on windows 10&lt;BR /&gt;
- Did not go into customize on windows installer GUI, but did put the win event stanza from documentation into the forwarder inputs.conf (system local).&lt;BR /&gt;
- opened 9997 data input in webui&lt;BR /&gt;
- Turned off windows firewall for troubleshooting.&lt;BR /&gt;
- Downloaded various windows apps/add-ons to splunk indexer thinking it was a deployment thing&lt;/P&gt;

&lt;P&gt;What am I missing?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 22:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294092#M55895</guid>
      <dc:creator>ShaunBaker</dc:creator>
      <dc:date>2017-11-22T22:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting the Windows universal forwarder to forward data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294093#M55896</link>
      <description>&lt;UL&gt;
&lt;LI&gt;is your outputs.conf correctly set up to forward data to the indexer?&lt;/LI&gt;
&lt;LI&gt;install the Splunk Add-on for Windows on the universal forwarder: &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;https://splunkbase.splunk.com/app/742/&lt;/A&gt;
The steps to install this on the universal forwarder are listed here: &lt;A href="https://docs.splunk.com/Documentation/WindowsAddOn/4.8.4/User/InstalltheSplunkAdd-onforWindows#Install_the_add-on_on_a_universal_forwarder"&gt;https://docs.splunk.com/Documentation/WindowsAddOn/4.8.4/User/InstalltheSplunkAdd-onforWindows#Install_the_add-on_on_a_universal_forwarder&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;The Add-on has all the right configuration to ingest windows events.  This needs to be installed on the universal forwarder so that the forwarder knows what information to push to the indexer.&lt;/P&gt;

&lt;P&gt;Typically, a deployment server is used to push this configuration to the universal forwarders.  You can read more about them here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Updating/Aboutdeploymentserver"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/Updating/Aboutdeploymentserver&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 22:58:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294093#M55896</guid>
      <dc:creator>mtulett_splunk</dc:creator>
      <dc:date>2017-11-22T22:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting the Windows universal forwarder to forward data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294094#M55897</link>
      <description>&lt;P&gt;I have the splunk add-on for windows on the indexer, am I supposed to move it form apps to deployment apps so that it can be used for a server class?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 01:25:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294094#M55897</guid>
      <dc:creator>ShaunBaker</dc:creator>
      <dc:date>2017-11-23T01:25:47Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting the Windows universal forwarder to forward data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294095#M55898</link>
      <description>&lt;P&gt;I've updated my answer with a link to the installation guide for universal forwarders.&lt;/P&gt;

&lt;P&gt;You can place the Add-on in deployment apps, but you will need to configure the universal forwarder to poll the indexer for configuration, as well as creating a server class for the server (this can be achieved through conf files or the GUI).&lt;/P&gt;

&lt;P&gt;I would suggest reading the 'About deployment server' documentation from the link in my answer if you are curious about this, as the topic is too large to properly cover in an answer here.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 02:18:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294095#M55898</guid>
      <dc:creator>mtulett_splunk</dc:creator>
      <dc:date>2017-11-23T02:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting the Windows universal forwarder to forward data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294096#M55899</link>
      <description>&lt;P&gt;I think I got it working- I copied the windows add-on over to deployment-apps and already had the client showing up in forwarder manager, so created a server class, added the windows app and after a while the windows logs finally started rolling in.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 08:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294096#M55899</guid>
      <dc:creator>ShaunBaker</dc:creator>
      <dc:date>2017-11-23T08:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble getting the Windows universal forwarder to forward data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294097#M55900</link>
      <description>&lt;P&gt;Great to hear!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 22:21:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Trouble-getting-the-Windows-universal-forwarder-to-forward-data/m-p/294097#M55900</guid>
      <dc:creator>mtulett_splunk</dc:creator>
      <dc:date>2017-11-23T22:21:27Z</dc:date>
    </item>
  </channel>
</rss>

