<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is the Windows universal forwarder not showing in forwarder management? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Windows-universal-forwarder-not-showing-in-forwarder/m-p/341150#M62882</link>
    <description>&lt;P&gt;msiexec.exe /i "splunkforwarder-7.0.3-fa31da744b51-x64-release.msi" ALLUSERS=1 /qn /norestart /log output.log RECEIVING_INDEXER="indexer:9997" DEPLOYMENT_SERVER="indexer:9997" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_APP_ENABLE=1 SERVICESTARTTYPE=auto LAUNCHSPLUNK=1 AGREETOLICENSE=Yes&lt;/P&gt;

&lt;P&gt;This did not get any data into splunk. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; So it was a step back. I replaced the real name of our indexer with just indexer. &lt;/P&gt;

&lt;P&gt;This got data into splunk but did not show up in the forwarder manager. &lt;/P&gt;

&lt;P&gt;msiexec.exe /i splunkuniversalforwarder_x86.msi RECEIVING_INDEXER="indexer1:9997" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 AGREETOLICENSE=Yes /quiet&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:05:22 GMT</pubDate>
    <dc:creator>Rebeccakettler</dc:creator>
    <dc:date>2020-09-29T19:05:22Z</dc:date>
    <item>
      <title>Why is the Windows universal forwarder not showing in forwarder management?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Windows-universal-forwarder-not-showing-in-forwarder/m-p/341149#M62881</link>
      <description>&lt;P&gt;I am trying to create a new universal package for our windows servers. The log data from our test server is showing up in Splunk the way it should; however, I don't see the server name in Forwarder Management. Our old package which was "lost" did populate the forwarder management list. &lt;BR /&gt;
Any troubleshooting recommendations or advice?&lt;BR /&gt;
We do not have server classes or apps configured in the deployment server at this time. The current forwarders only show as clients. &lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 16:41:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Windows-universal-forwarder-not-showing-in-forwarder/m-p/341149#M62881</guid>
      <dc:creator>Rebeccakettler</dc:creator>
      <dc:date>2018-04-18T16:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Windows universal forwarder not showing in forwarder management?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Windows-universal-forwarder-not-showing-in-forwarder/m-p/341150#M62882</link>
      <description>&lt;P&gt;msiexec.exe /i "splunkforwarder-7.0.3-fa31da744b51-x64-release.msi" ALLUSERS=1 /qn /norestart /log output.log RECEIVING_INDEXER="indexer:9997" DEPLOYMENT_SERVER="indexer:9997" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 WINEVENTLOG_APP_ENABLE=1 SERVICESTARTTYPE=auto LAUNCHSPLUNK=1 AGREETOLICENSE=Yes&lt;/P&gt;

&lt;P&gt;This did not get any data into splunk. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; So it was a step back. I replaced the real name of our indexer with just indexer. &lt;/P&gt;

&lt;P&gt;This got data into splunk but did not show up in the forwarder manager. &lt;/P&gt;

&lt;P&gt;msiexec.exe /i splunkuniversalforwarder_x86.msi RECEIVING_INDEXER="indexer1:9997" WINEVENTLOG_SEC_ENABLE=1 WINEVENTLOG_SYS_ENABLE=1 AGREETOLICENSE=Yes /quiet&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:05:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Windows-universal-forwarder-not-showing-in-forwarder/m-p/341150#M62882</guid>
      <dc:creator>Rebeccakettler</dc:creator>
      <dc:date>2020-09-29T19:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why is the Windows universal forwarder not showing in forwarder management?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Windows-universal-forwarder-not-showing-in-forwarder/m-p/341151#M62883</link>
      <description>&lt;P&gt;Ended up just using the second string with a few additional windows logs enabled. No deployment server. We can alter the config with out patching system so we will continue to do that for now. &lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 17:44:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-the-Windows-universal-forwarder-not-showing-in-forwarder/m-p/341151#M62883</guid>
      <dc:creator>Rebeccakettler</dc:creator>
      <dc:date>2018-05-18T17:44:20Z</dc:date>
    </item>
  </channel>
</rss>

