<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder, Server Class. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302487#M57129</link>
    <description>&lt;P&gt;Yes, I restarted and port is open.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Nov 2017 11:58:42 GMT</pubDate>
    <dc:creator>test_qweqwe</dc:creator>
    <dc:date>2017-11-23T11:58:42Z</dc:date>
    <item>
      <title>Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302485#M57127</link>
      <description>&lt;P&gt;I install UF on linux client.&lt;BR /&gt;
Than I &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk set deploy-poll *.*.*.*:8089
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Client did not appear in Forwarder Management in Clients.&lt;/P&gt;

&lt;P&gt;What i miss?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 11:20:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302485#M57127</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-23T11:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302486#M57128</link>
      <description>&lt;P&gt;Hi test_qweqwe,&lt;BR /&gt;
did you restarted Splunk?&lt;BR /&gt;
did you checked if port 8089 is open (telnet xx.xx.xx.xx 8089)&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 11:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302486#M57128</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-23T11:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302487#M57129</link>
      <description>&lt;P&gt;Yes, I restarted and port is open.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 11:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302487#M57129</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-23T11:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302488#M57130</link>
      <description>&lt;P&gt;check in $SPLUNK_HOME/etc/system/local/server.conf and $SPLUNK_HOME/etc/system/local/inputs.conf if hostname is correct or is duplicated with another machine.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:56:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302488#M57130</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-29T16:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302489#M57131</link>
      <description>&lt;P&gt;Verify that it created &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/deploymentclient.conf&lt;/CODE&gt; and that it is correct.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 16:08:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302489#M57131</guid>
      <dc:creator>lycollicott</dc:creator>
      <dc:date>2017-11-23T16:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302490#M57132</link>
      <description>&lt;P&gt;All is good.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 18:12:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302490#M57132</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-25T18:12:46Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302491#M57133</link>
      <description>&lt;P&gt;deploymentclient.conf created and it's correct.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 18:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302491#M57133</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-25T18:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302492#M57134</link>
      <description>&lt;P&gt;Try to manually install an outputs.conf to send logs to indexers and see if forwarder sends logs.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 18:24:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302492#M57134</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-25T18:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302493#M57135</link>
      <description>&lt;P&gt;The problem was in AWS Security policis which was block ports. Now my client is in Forwarder Management.&lt;BR /&gt;
But the problem is that I accidentally removed $SPLUNK_HOME/etc/system/local/outputs.conf&lt;/P&gt;

&lt;P&gt;It's big problem or not?&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 20:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302493#M57135</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-25T20:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302494#M57136</link>
      <description>&lt;P&gt;Normally &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/outputs.conf&lt;/CODE&gt; is empty while &lt;CODE&gt;$SPLUNK_HOME/etc/apps/&amp;lt;your deployment app&amp;gt;/local/outputs.conf&lt;/CODE&gt; has the output information. &lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 22:16:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302494#M57136</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-11-25T22:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302495#M57137</link>
      <description>&lt;P&gt;Hi test_qweqwe,&lt;BR /&gt;
the best approach to outputs.conf is to create a Technical Add-On (TA) containing only outputs.conf to deploy using a Deployment server, so you can centrally manage your outputs.conf.&lt;/P&gt;

&lt;P&gt;But if you have the described problem you can manually create your outputs.conf in two ways: &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;copying from an example ( see &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Outputsconf"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Admin/Outputsconf&lt;/A&gt; )&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;launching by CLI the following command&lt;/P&gt;

&lt;P&gt;./splunk add forward-server &lt;HOST name="" or="" ip="" address=""&gt;:&lt;LISTENING port=""&gt;&lt;/LISTENING&gt;&lt;/HOST&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;in both the cases restart Splunk.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 10:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302495#M57137</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-26T10:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302496#M57138</link>
      <description>&lt;P&gt;In my UF I used this command: ./splunk add monitor /var/log&lt;BR /&gt;
And it's created stanza [monitor///] in /opt/splunkforwarder/etc/apps/search/local/inputs.conf&lt;/P&gt;

&lt;P&gt;How me easy create TA in my deployment server to send it to UF?&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 17:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302496#M57138</guid>
      <dc:creator>test_qweqwe</dc:creator>
      <dc:date>2017-11-26T17:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder, Server Class.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302497#M57139</link>
      <description>&lt;P&gt;Hi test_qweqwe,&lt;BR /&gt;
It isn't so easy to describe in few words!&lt;BR /&gt;
Follow the instructions on &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Updating/Aboutdeploymentserver"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Updating/Aboutdeploymentserver&lt;/A&gt; to understand how Deployment Server works and how to configure and use it.&lt;/P&gt;

&lt;P&gt;Anyway, in your last comment you spoke about a different things, the command &lt;CODE&gt;./splunk add monitor /var/log&lt;/CODE&gt; is useful to add a monitor stanza to inputs.conf, instead I spoke about outputs.conf, that is the way to say to the forwarder which are the indexer to send data.&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 07:49:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Server-Class/m-p/302497#M57139</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-27T07:49:13Z</dc:date>
    </item>
  </channel>
</rss>

