<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot figure Universal forwarder out in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-figure-Universal-forwarder-out/m-p/35808#M6511</link>
    <description>&lt;P&gt;I have done 3-4 days of research and have been striking out.  Here is the process that I follow.  I install the universal forwarder on our web server to monitor system logs.  Below are the steps:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;I execute the installable msi file from cmd prompt to create the service and start the installation process.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I install the UF to C:\Program Files\SplunkUniversalForwarder\&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I leave the deployment server blank.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Now for recieiving indexer the main splunk cleint is on z8 so I ping z8 get the IP address and put that in as the host name and assign it to port 9997 which is the default port..  is this correct?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I leave the SSL certificate informaiton blank,&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I choose local data only.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I select system log and browse to the directory path for thwere the websites IIS logs are pointing and install the service.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;From here I do not know what to do.  Any help would be appreciated.  Am I doing this right?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jun 2011 15:25:08 GMT</pubDate>
    <dc:creator>chrisscott1</dc:creator>
    <dc:date>2011-06-28T15:25:08Z</dc:date>
    <item>
      <title>Cannot figure Universal forwarder out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-figure-Universal-forwarder-out/m-p/35808#M6511</link>
      <description>&lt;P&gt;I have done 3-4 days of research and have been striking out.  Here is the process that I follow.  I install the universal forwarder on our web server to monitor system logs.  Below are the steps:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;&lt;P&gt;I execute the installable msi file from cmd prompt to create the service and start the installation process.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I install the UF to C:\Program Files\SplunkUniversalForwarder\&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I leave the deployment server blank.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Now for recieiving indexer the main splunk cleint is on z8 so I ping z8 get the IP address and put that in as the host name and assign it to port 9997 which is the default port..  is this correct?&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I leave the SSL certificate informaiton blank,&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I choose local data only.&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;I select system log and browse to the directory path for thwere the websites IIS logs are pointing and install the service.&lt;/P&gt;&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;From here I do not know what to do.  Any help would be appreciated.  Am I doing this right?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jun 2011 15:25:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-figure-Universal-forwarder-out/m-p/35808#M6511</guid>
      <dc:creator>chrisscott1</dc:creator>
      <dc:date>2011-06-28T15:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot figure Universal forwarder out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Cannot-figure-Universal-forwarder-out/m-p/35809#M6512</link>
      <description>&lt;P&gt;Have you told the Splunk server (z8) to listen for information from a forwarder? Go to Manager - Forwarding and Receiving to turn on receiving. Make sure to download the Deployment Monitor app to keep an eye on it as well.&lt;/P&gt;

&lt;P&gt;You can look for relevant events in the _internal index to troubleshoot - try searching&lt;BR /&gt;&lt;BR /&gt;
    &lt;CODE&gt;index=_internal sourcetype="splunkd"&lt;/CODE&gt;&lt;BR /&gt;&lt;BR /&gt;
for starters.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:45:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Cannot-figure-Universal-forwarder-out/m-p/35809#M6512</guid>
      <dc:creator>FunPolice</dc:creator>
      <dc:date>2020-09-28T09:45:38Z</dc:date>
    </item>
  </channel>
</rss>

