<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to forward data to a Splunk Free license? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308325#M58074</link>
    <description>&lt;P&gt;Thanks&lt;BR /&gt;
 nickhillscpl : Yes I have configured Receiver, Yes I opened port 9997 on firewall for TCP ( should it be udp?)&lt;BR /&gt;
No I have not configured any this special on indexer. on the tutorial video there is no mention of setting indexer.&lt;BR /&gt;
Where could I find this?&lt;/P&gt;

&lt;P&gt;HiroshiSatoh : I only access data from search head. When i click on "data summary" I can see other host I used in the past but I cannot see the ip of forwarding server. this is available on the fulled licensed server.&lt;/P&gt;

&lt;P&gt;Is there some log on the Forwarding server I could look telling me "cannot contact indexer because..."?&lt;/P&gt;</description>
    <pubDate>Mon, 16 Oct 2017 10:32:58 GMT</pubDate>
    <dc:creator>pdevosceazure</dc:creator>
    <dc:date>2017-10-16T10:32:58Z</dc:date>
    <item>
      <title>Is it possible to forward data to a Splunk Free license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308321#M58070</link>
      <description>&lt;P&gt;I am trying to forward logs from a linux server to a Splunk Free indexer instance.&lt;BR /&gt;
I know my forwarder is set up correctly because I can forward data to a fully licensed splunk indexer OK.&lt;BR /&gt;
But when I switch the target server to the free license indexer i don't receive anything.&lt;/P&gt;

&lt;P&gt;Q: Is it possible to use universal forwarder to send data to a splunk free indexer ( not a trial license)?&lt;BR /&gt;
I have seen a good few answers but they all talk about forwarding FROM Splunk free not forwarding TO splunk free.&lt;BR /&gt;
I have seen the "MoreaboutSplunkFree" page &lt;BR /&gt;
 &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/MoreaboutSplunkFree&lt;/A&gt;&lt;BR /&gt;
but again restrictions seem to be about about forwarding &lt;STRONG&gt;from&lt;/STRONG&gt; not &lt;STRONG&gt;to&lt;/STRONG&gt; Splunk free.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 09:05:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308321#M58070</guid>
      <dc:creator>pdevosceazure</dc:creator>
      <dc:date>2017-10-16T09:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to forward data to a Splunk Free license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308322#M58071</link>
      <description>&lt;P&gt;You should be able to do this - as you correctly state, the free version limits your ability to configure a distributed environment (hence &lt;STRONG&gt;From&lt;/STRONG&gt;).&lt;/P&gt;

&lt;P&gt;There are no restrictions using a UF to send data &lt;STRONG&gt;to&lt;/STRONG&gt; a system running the free licence.&lt;/P&gt;

&lt;P&gt;Silly questions therefore follow:&lt;BR /&gt;
Have you configured receiving ports?&lt;BR /&gt;
Indexes?&lt;BR /&gt;
Firewalls?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 10:18:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308322#M58071</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-16T10:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to forward data to a Splunk Free license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308323#M58072</link>
      <description>&lt;P&gt;What is the reason?&lt;BR /&gt;
Data is transferred to the indexer, but it can not be retrieved from the search head.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 10:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308323#M58072</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2017-10-16T10:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to forward data to a Splunk Free license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308324#M58073</link>
      <description>&lt;P&gt;In Splunk "free" there is no search head/indexer - Its a single box deployment only...&lt;BR /&gt;
Although... that raises a good question if you were on Ent Trial, and had previously configured distributed search before the lic reverted to free&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 10:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308324#M58073</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-16T10:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to forward data to a Splunk Free license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308325#M58074</link>
      <description>&lt;P&gt;Thanks&lt;BR /&gt;
 nickhillscpl : Yes I have configured Receiver, Yes I opened port 9997 on firewall for TCP ( should it be udp?)&lt;BR /&gt;
No I have not configured any this special on indexer. on the tutorial video there is no mention of setting indexer.&lt;BR /&gt;
Where could I find this?&lt;/P&gt;

&lt;P&gt;HiroshiSatoh : I only access data from search head. When i click on "data summary" I can see other host I used in the past but I cannot see the ip of forwarding server. this is available on the fulled licensed server.&lt;/P&gt;

&lt;P&gt;Is there some log on the Forwarding server I could look telling me "cannot contact indexer because..."?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 10:32:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308325#M58074</guid>
      <dc:creator>pdevosceazure</dc:creator>
      <dc:date>2017-10-16T10:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to forward data to a Splunk Free license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308326#M58075</link>
      <description>&lt;P&gt;try searching for: &lt;CODE&gt;index=_internal host=&amp;lt;your missing host name&amp;gt;&lt;/CODE&gt;&lt;BR /&gt;
Although I suspect that it may come back empty!&lt;BR /&gt;
Then take a look at the &lt;CODE&gt;/opt/splunkforwarder/var/log/splunk/splunkd.log&lt;/CODE&gt; file - Look for any connection attempts specifically to port 9997. (yes it is normally TCP)&lt;/P&gt;

&lt;P&gt;How did you configure your forwarder?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 13:06:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308326#M58075</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-10-16T13:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to forward data to a Splunk Free license?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308327#M58076</link>
      <description>&lt;P&gt;Distributed configuration is not possible with the free version. Can you search on the indexer's server?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2017 13:27:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-forward-data-to-a-Splunk-Free-license/m-p/308327#M58076</guid>
      <dc:creator>HiroshiSatoh</dc:creator>
      <dc:date>2017-10-16T13:27:27Z</dc:date>
    </item>
  </channel>
</rss>

