<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder on Windows in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296093#M56155</link>
    <description>&lt;P&gt;so I have it forwarding now, I was missing an inputs.conf configuration. It was out of box default, I guess.&lt;/P&gt;

&lt;P&gt;what I do have a question is the folder structure.&lt;/P&gt;

&lt;P&gt;My other Windows server has as custom configuration folder, that I think was pushed to it from the deployment server? &lt;/P&gt;

&lt;P&gt;I am not really sure since we had a consultant set all this up and I haven't had any training to date.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Aug 2017 11:57:13 GMT</pubDate>
    <dc:creator>pfabrizi</dc:creator>
    <dc:date>2017-08-22T11:57:13Z</dc:date>
    <item>
      <title>Universal Forwarder on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296089#M56151</link>
      <description>&lt;P&gt;I am testing install of universal forwarder for windows. I am running 6.5.1 enterprise splunk but the universal forwarder I installed on windows is 6.6.2. &lt;/P&gt;

&lt;P&gt;I get these errors:&lt;BR /&gt;
is a compatibility issue?&lt;/P&gt;

&lt;P&gt;8-21-2017 13:16:00.593 -0400 WARN  TcpOutputFd - Connect to 10.83.180.135:9997 failed. A socket operation was attempted to an unreachable network.&lt;/P&gt;

&lt;P&gt;8-21-2017 13:16:00.593 -0400 ERROR TcpOutputFd - Connection to host=10.83.180.135:9997 failed&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 17:46:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296089#M56151</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2017-08-21T17:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296090#M56152</link>
      <description>&lt;P&gt;using a few assumptions, i'm going to guess that 10.83.180.135 is your indexer? (port 9997 is the default data port) &lt;/P&gt;

&lt;P&gt;If that's the case, there's a connectivity issue between the two machines. Try telnet tests / ssh tests and resolve as a standard connectivity issue. &lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 17:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296090#M56152</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2017-08-21T17:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296091#M56153</link>
      <description>&lt;P&gt;It's not a compatibility issue, it's an issue with your forwarder connecting to your indexer. Did you enable receiving on the indexer? If not, go to &lt;CODE&gt;Settings &amp;gt; Forwarding &amp;amp; Receiving &amp;gt; Enable Receiving&lt;/CODE&gt; and add port 9997 to listen&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2017 20:13:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296091#M56153</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-08-21T20:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296092#M56154</link>
      <description>&lt;P&gt;I have other windows servers sending on 9997. I do have a question on which outputs.conf gets used.&lt;BR /&gt;
I have 3 of them.&lt;/P&gt;

&lt;P&gt;etc\apps\splunkuniversalforwarder\default&lt;BR /&gt;
etc\system\default&lt;BR /&gt;
etc\system\local  - this is the one I changed.&lt;/P&gt;

&lt;P&gt;where should it be?&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 10:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296092#M56154</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2017-08-22T10:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296093#M56155</link>
      <description>&lt;P&gt;so I have it forwarding now, I was missing an inputs.conf configuration. It was out of box default, I guess.&lt;/P&gt;

&lt;P&gt;what I do have a question is the folder structure.&lt;/P&gt;

&lt;P&gt;My other Windows server has as custom configuration folder, that I think was pushed to it from the deployment server? &lt;/P&gt;

&lt;P&gt;I am not really sure since we had a consultant set all this up and I haven't had any training to date.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2017 11:57:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296093#M56155</guid>
      <dc:creator>pfabrizi</dc:creator>
      <dc:date>2017-08-22T11:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder on Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296094#M56156</link>
      <description>&lt;P&gt;You will likely need some training my friend. I suggest the administration course.  Check here:&lt;BR /&gt;
&lt;A href="https://www.splunk.com/view/SP-CAAAAH9?ac=News_Feb09_EDU" target="_blank"&gt;https://www.splunk.com/view/SP-CAAAAH9?ac=News_Feb09_EDU&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;the only folders that override /$SPLUNK_HOME/etc/apps/ are&lt;BR /&gt;
$SPLUNK_HOME/etc/system/&lt;/P&gt;

&lt;P&gt;also, there should never be a reason to touch /etc/system/default. bad things can happen if you mess up there and there's no fall back. you changed the right one in /etc/system/local.  Always make changes there. &lt;/P&gt;

&lt;P&gt;if you have conflicting configurations, it's common that there's something in /etc/system/local. &lt;/P&gt;

&lt;P&gt;folder priority is a pretty dense topic with splunk, and depends heavily on your architecture. &lt;/P&gt;

&lt;P&gt;Also... if you manipulated your forwarder manually, you may want to check others for a deploymentclient.conf file somewhere either in /etc/system/apps/  OR in /etc/system/local. &lt;/P&gt;

&lt;P&gt;If you're using a DS, there is a default configuration ANY windows forwarder will pull down as soon as it connects. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:28:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-on-Windows/m-p/296094#M56156</guid>
      <dc:creator>tmarlette</dc:creator>
      <dc:date>2020-09-29T15:28:56Z</dc:date>
    </item>
  </channel>
</rss>

