<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal forwarder (Windows) does not send logs even though &amp;quot;active&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376458#M68141</link>
    <description>&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;check etc/apps/ on the UF to confirm the inputs configuration was indeed correctly pushed from your deployment server --&amp;gt;&lt;STRONG&gt;It is showing the index name which has been created.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;check splunkd.log on both splunk instances for errors &lt;BR /&gt;
In Splunk OVA(Linux System) --&amp;gt; &lt;STRONG&gt;WARN Tcpoutput - Forwarding the indexer group xxxxxx blocked for &lt;BR /&gt;
xxxx seconds&lt;/STRONG&gt;&lt;BR /&gt;
In Windows System --&amp;gt; &lt;STRONG&gt;There is no error&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Are the internal logs from the UF getting forwarded to the Enterprise instance? --&amp;gt; &lt;STRONG&gt;No&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;confirm universal forwarder runs under an account that has permissions to read the event logs --&amp;gt; &lt;STRONG&gt;checked and it is running as SYSTEM User.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 08 May 2018 10:38:48 GMT</pubDate>
    <dc:creator>Sagar0511</dc:creator>
    <dc:date>2018-05-08T10:38:48Z</dc:date>
    <item>
      <title>Universal forwarder (Windows) does not send logs even though "active"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376456#M68139</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;

&lt;P&gt;I am testing log forwarding using universal forwarder from Windows to Splunk but can't seem to receive any logs.&lt;BR /&gt;
My test environment has Splunk Enterprise OVA (standalone) as server and Windows 2012 (with universal forwarder) as client.&lt;/P&gt;

&lt;P&gt;Steps i followed (not necessarily in that order):&lt;/P&gt;

&lt;P&gt;On Windows client (Universal forwarder):&lt;BR /&gt;
* Installed Universal forwarder&lt;BR /&gt;
* configured as deployment client&lt;BR /&gt;
* Added firewall rule to allow destination port 9997&lt;BR /&gt;
* checked using "splunk list forward-server" to confirm server is listed in "active" section&lt;/P&gt;

&lt;P&gt;On Splunk OVA enterprise server&lt;BR /&gt;
* Configured listening on port 9997 using web console&lt;BR /&gt;
* Added forwarder input using Settings -&amp;gt; "Data Inputs" -&amp;gt; "Forwarded Inputs" -&amp;gt; "Windows Event Logs" (could see my desired deployment client in the list). Selected Application, security &amp;amp; system events&lt;BR /&gt;
* Stopped iptables service (just to ensure its not blocking traffic)&lt;BR /&gt;
* Followed &lt;A href="https://answers.splunk.com/answers/49833/splunk-forwarder-connection-refused-from-splunk-indexer.html"&gt;this&lt;/A&gt; link to receive logs from forwarder&lt;/P&gt;

&lt;P&gt;Testing:&lt;BR /&gt;
* created user in windows (client) and checked local event logs. Local log can be seen in "Security" events&lt;BR /&gt;
* Ran search in server (web console) to see this event. It says "no events found" for the specific index&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 06:10:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376456#M68139</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2018-05-08T06:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder (Windows) does not send logs even though "active"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376457#M68140</link>
      <description>&lt;UL&gt;
&lt;LI&gt;check etc/apps/ on the UF to confirm the inputs configuration was indeed correctly pushed from your deployment server&lt;/LI&gt;
&lt;LI&gt;check splunkd.log on both splunk instances for errors (+ are the internal logs from the UF getting forwarded to the Enterprise instance?)&lt;/LI&gt;
&lt;LI&gt;search for All Time, to rule out timestamping/sync issues&lt;/LI&gt;
&lt;LI&gt;confirm universal forwarder runs under an account that has permissions to read the event logs&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 08 May 2018 07:47:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376457#M68140</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-05-08T07:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder (Windows) does not send logs even though "active"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376458#M68141</link>
      <description>&lt;UL&gt;
&lt;LI&gt;&lt;P&gt;check etc/apps/ on the UF to confirm the inputs configuration was indeed correctly pushed from your deployment server --&amp;gt;&lt;STRONG&gt;It is showing the index name which has been created.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;check splunkd.log on both splunk instances for errors &lt;BR /&gt;
In Splunk OVA(Linux System) --&amp;gt; &lt;STRONG&gt;WARN Tcpoutput - Forwarding the indexer group xxxxxx blocked for &lt;BR /&gt;
xxxx seconds&lt;/STRONG&gt;&lt;BR /&gt;
In Windows System --&amp;gt; &lt;STRONG&gt;There is no error&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;Are the internal logs from the UF getting forwarded to the Enterprise instance? --&amp;gt; &lt;STRONG&gt;No&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;P&gt;confirm universal forwarder runs under an account that has permissions to read the event logs --&amp;gt; &lt;STRONG&gt;checked and it is running as SYSTEM User.&lt;/STRONG&gt;&lt;/P&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 08 May 2018 10:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376458#M68141</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2018-05-08T10:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder (Windows) does not send logs even though "active"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376459#M68142</link>
      <description>&lt;P&gt;Why is your indexer reporting warnings on tcpoutput to an indexer group? Or did this warning actually come from the windows box?&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 11:35:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376459#M68142</guid>
      <dc:creator>FrankVl</dc:creator>
      <dc:date>2018-05-08T11:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder (Windows) does not send logs even though "active"</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376460#M68143</link>
      <description>&lt;P&gt;I was able to fix the mentioned problem which was I was facing (for solving the forwarder not sending the logs though it is "active") from one of the reference &lt;A href="https://answers.splunk.com/answers/395859/how-to-fix-error-forwarding-to-indexer-group-defau.html"&gt;link&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 06:35:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-Windows-does-not-send-logs-even-though-quot/m-p/376460#M68143</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2018-05-10T06:35:20Z</dc:date>
    </item>
  </channel>
</rss>

