<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder with Sysmon not forwarding Correctly in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313378#M58737</link>
    <description>&lt;P&gt;Hi hardikJsheth,&lt;/P&gt;

&lt;P&gt;My guest 1 was configured to listen on port 9997.  Do I need to do anything on "Configure Forwarding"?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3216i309AA88499A66B0B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;My guest 2 universal forwarder output.conf default with the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = 10.0.2.4:9997

[tcpout-server://10.0.2.4:9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I just appended the following below:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [tcpout:eis_clustered_indexers]
 [tcpout-server://10.0.2.4:9998]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Results: No results. &lt;/P&gt;</description>
    <pubDate>Fri, 14 Jul 2017 07:55:32 GMT</pubDate>
    <dc:creator>wuming79</dc:creator>
    <dc:date>2017-07-14T07:55:32Z</dc:date>
    <item>
      <title>Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313376#M58735</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I'm trying to study the activities of some Malware thus I created the following environment using virtualbox. But I could not get the forwarder to work correctly. I could only get 1 event when I reboot guest 2. Did I miss out some other configurations?&lt;/P&gt;

&lt;P&gt;**&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Host&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;**&lt;BR /&gt;
Disable VirtualBox Host-Only Network so that Guest and Host could not ping each other but Guest can guest to guest.&lt;/P&gt;

&lt;P&gt;**&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Guest 1:&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;**&lt;BR /&gt;
IE8WIN7, SP1, IE Version 8.0.7601.17514&lt;BR /&gt;
Network: Nat Network&lt;BR /&gt;
IP: 10.0.2.15&lt;BR /&gt;
Installed Splunk Enterprise&lt;BR /&gt;
Open port 9998 to receive events (set up at &lt;A href="http://localhost:8000/en-US/manager/search/data/inputs/tcp/cooked"&gt;http://localhost:8000/en-US/manager/search/data/inputs/tcp/cooked&lt;/A&gt;)&lt;BR /&gt;
Set Firewall to allow inbound and outbound 10.0.2.4 and port 9998.&lt;/P&gt;

&lt;P&gt;**&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Guest 2:&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;**&lt;BR /&gt;
IE8WIN7, SP1, IE Version 8.0.7601.17514&lt;BR /&gt;
IP: 10.0.2.4&lt;BR /&gt;
Installed Splunk Universal Forwarder&lt;BR /&gt;
Install sysmon via CLI "sysmon -i -n -accepteula" &lt;BR /&gt;
Added  the following into universal forwarder input.conf&lt;/P&gt;

&lt;P&gt;"[WinEventLog://Microsoft-Windows-Sysmon/Operational]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
renderXml = true"&lt;/P&gt;

&lt;P&gt;Set Firewall to allow inbound and outbound 10.0.2.15 and port 9998.&lt;/P&gt;

&lt;P&gt;I only got 1 event after Guest 2 reboots. After that, no matter what programs I open in Guest 2, there is no events seens from Guest 1. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3219iF71BFBE85CA07A80/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 03:18:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313376#M58735</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-07-14T03:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313377#M58736</link>
      <description>&lt;P&gt;What you need to do is enable receiving on your guest 1. For login to Guest 1 splunk web ui, go to Settings --&amp;gt; Forwarding And Receiving  and configure receiving.&lt;/P&gt;

&lt;P&gt;On Guest 2 where you have installed universal forwarder, add outputs.conf entry to enable UF to forward data to Splunk Enterprise server.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:eis_clustered_indexers]
server = ip_address:port
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Jul 2017 06:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313377#M58736</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-07-14T06:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313378#M58737</link>
      <description>&lt;P&gt;Hi hardikJsheth,&lt;/P&gt;

&lt;P&gt;My guest 1 was configured to listen on port 9997.  Do I need to do anything on "Configure Forwarding"?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3216i309AA88499A66B0B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;My guest 2 universal forwarder output.conf default with the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = 10.0.2.4:9997

[tcpout-server://10.0.2.4:9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I just appended the following below:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [tcpout:eis_clustered_indexers]
 [tcpout-server://10.0.2.4:9998]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Results: No results. &lt;/P&gt;</description>
      <pubDate>Fri, 14 Jul 2017 07:55:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313378#M58737</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-07-14T07:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313379#M58738</link>
      <description>&lt;P&gt;I have uninstall and reinstall universal forwarder without indicating deployment server and receiving information.&lt;BR /&gt;
I then tried to follow the instructions at &lt;A href="https://answers.splunk.com/answers/126122/no-available-server-list-on-opt-splunkforwarder-bin-splunk-list-forward-server.html"&gt;https://answers.splunk.com/answers/126122/no-available-server-list-on-opt-splunkforwarder-bin-splunk-list-forward-server.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I went to check my Guest 1, and still nothing from Guest B... I reboot Guest B and it seems that I have also lost the initial event that I saw previously (in first post).&lt;/P&gt;

&lt;P&gt;I went to check C:\Program Files\SplunkUniversalForwarder\etc\system\local &lt;BR /&gt;
my input.conf and output.conf are as below:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;input.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = IE8Win7

[WinEventLog://Microsoft-Windows-Sysmon/Operational]
disabled = false
renderXml = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;output.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]
server = 10.0.2.4:9997
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 17 Jul 2017 15:09:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313379#M58738</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-07-17T15:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313380#M58739</link>
      <description>&lt;P&gt;Do I just need to set allow TCP port 9997 (local and remote) in outbound rule in guest 1 and  set allow TCP port 9997 (local and remote) in outbound rule in guest 2? &lt;BR /&gt;
Do I actually need to set allow IP 10.0.2.4 (local and remote) in outbound rule in Guest 1 and set allow IP 10.0.2.15 (local and remote) in outbound rule in Guest 2?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 02:24:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313380#M58739</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-07-18T02:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313381#M58740</link>
      <description>&lt;P&gt;You are sending data from Guest 2 to Guest 1 on 9997. You need to enable inbound traffic on guest 1 for port 9997 and outbound traffic on guest 2 to 9997.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 05:41:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313381#M58740</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-07-18T05:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313382#M58741</link>
      <description>&lt;P&gt;Hi, I tried enable inbound traffic on guest 1 for port 9997 TCP and UDP and outbound traffic on guest 2 to 9997 TCP and UDP but still no data..&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 06:00:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313382#M58741</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-07-18T06:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313383#M58742</link>
      <description>&lt;P&gt;I saw the following msg in splunkd.log on guest1.&lt;BR /&gt;
ERROR ExecProcessor - message from ""C:\Program Files\Splunk\bin\splunk-winevtlog.exe"" splunk-winevtlog - WinEventMon::configure: Failed to find Event Log with channel name='Microsoft-Windows-Sysmon/Operational'&lt;/P&gt;

&lt;P&gt;Does this mean guest2 has forworded something over to guest1 but still can't find event log?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 15:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313383#M58742</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-07-18T15:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313384#M58743</link>
      <description>&lt;P&gt;I tried the cmd "splunk list forward-server" in SplunkUniversalForwarder/bin to check the connection, after entering my userId and password, it just came back to DOS and shows nothing. I have another VMWare using vmnet8 adapter and I was able to forward my sysmon out. The cmd "splunk list forward-server" was able to see active connections. What could possibility be the issue? Virtualbox incompatible issue?? &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3218iD1EA84BBEDE361A8/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2017 04:38:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313384#M58743</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-07-19T04:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313385#M58744</link>
      <description>&lt;P&gt;Just for record since I didn't find any answers on this subject yet.&lt;BR /&gt;
The reason why splunk list forward-server was because my cmd was not executed as administration. &lt;BR /&gt;
When I executed as administrated, I could see my IP and port configured and active. &lt;/P&gt;

&lt;P&gt;Now the issue again...so list forward-server listed my ip port as configured and active and I had allow the ports to communicate between the 2 guest, why didn't the data came in?&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2017 08:13:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313385#M58744</guid>
      <dc:creator>wuming79</dc:creator>
      <dc:date>2017-07-22T08:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder with Sysmon not forwarding Correctly</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313386#M58745</link>
      <description>&lt;P&gt;Not trying to revive a dead post, however if others are facing the same problem. Check the name of the .conf files created. You listed your files as input.conf and output.conf. The correct file name is input*&lt;EM&gt;s&lt;/EM&gt;&lt;EM&gt;.conf and output&lt;/EM&gt;&lt;EM&gt;s&lt;/EM&gt;*.conf.&lt;/P&gt;

&lt;P&gt;Fix the file name and you probably would have your problem solved.&lt;/P&gt;

&lt;P&gt;,Don't want to revive a dead post, however you may have had issues with the names of your .conf files. You listed them as input.conf and output.conf NOT input*&lt;EM&gt;s&lt;/EM&gt;&lt;EM&gt;.conf and output&lt;/EM&gt;&lt;EM&gt;s&lt;/EM&gt;*.conf&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:50:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-with-Sysmon-not-forwarding-Correctly/m-p/313386#M58745</guid>
      <dc:creator>Phrack</dc:creator>
      <dc:date>2020-09-29T22:50:59Z</dc:date>
    </item>
  </channel>
</rss>

