<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal forwarder issue in AWS in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381363#M68793</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have one more problem, I am only able to see the logs from my folder on universal forwarder:&lt;/P&gt;

&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk&lt;/P&gt;

&lt;P&gt;Apart from it am not able to see any folder logs&lt;/P&gt;

&lt;P&gt;Can you please suggest something on this?&lt;/P&gt;</description>
    <pubDate>Wed, 20 Feb 2019 12:47:49 GMT</pubDate>
    <dc:creator>partix2</dc:creator>
    <dc:date>2019-02-20T12:47:49Z</dc:date>
    <item>
      <title>Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381355#M68785</link>
      <description>&lt;P&gt;Hi , i have created 2 instances  of windows in AWS and using one of the instance using universal forwarder to forward the logs on another windows instance of splunk enterprise as my indexer. But the logs are not getting forwarded and i can see the service of forwarder running on my Universal forwarder instance.Also i have enabled the receiving port 9997 on my indexer. What can be probable reason for the same?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 12:32:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381355#M68785</guid>
      <dc:creator>partix2</dc:creator>
      <dc:date>2019-02-13T12:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381356#M68786</link>
      <description>&lt;P&gt;It could be a lot of reasons. Did you configure outputs.conf? Did you configure network setting? Are instances able to ping each other?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 13:46:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381356#M68786</guid>
      <dc:creator>eduardKiyko</dc:creator>
      <dc:date>2019-02-13T13:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381357#M68787</link>
      <description>&lt;P&gt;In reverse probable order:&lt;/P&gt;

&lt;P&gt;1.) Did you configure an AWS security group to allow your UF to send outbound traffic on port 9997&lt;BR /&gt;
2.) Did you configure an AWS security group to allow your Indexer to receive inbound traffic on 9997&lt;BR /&gt;
3.) Have you configured Windows Firewall to allow the same?&lt;BR /&gt;
4.) Did you configure the forwarder to forward events to the indexer on 9997? - Did you use the ui, or did you set an ouputs.conf config? - Can you post the config?&lt;BR /&gt;
5.) Does netstat show the UF trying to open port 9997 to send data on the UF?&lt;BR /&gt;
6.) Does netstat show the indexer listening on port 9997?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 14:46:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381357#M68787</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-02-13T14:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381358#M68788</link>
      <description>&lt;P&gt;Hi , my comments for your concerns are listed as below:&lt;BR /&gt;
1.  Did you configure an AWS security group to allow your UF to send outbound traffic on port 9997  -- YES&lt;BR /&gt;
2.  Did you configure an AWS security group to allow your Indexer to receive inbound traffic on 9997 -- YES&lt;BR /&gt;
3.  Have you configured Windows Firewall to allow the same? -- YES&lt;BR /&gt;
4.  Did you configure the forwarder to forward events to the indexer on 9997? – YES&lt;BR /&gt;
5.   Did you use the ui, or did you set an ouputs.conf config? – I used UI to configure forwarding to the indexer.&lt;BR /&gt;
6.  Can you post the config? – The outputs.conf from indexer instance in the folder “C:\Program Files\SplunkUniversalForwarder\etc\system\local”  is as below:&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = default-autolb-group&lt;BR /&gt;
[tcpout:default-autolb-group]&lt;BR /&gt;
server = 172.31.88.99:9997&lt;BR /&gt;
[tcpout-server://172.31.88.99:9997]&lt;BR /&gt;
7.  Does netstat show the UF trying to open port 9997 to send data on the UF?- Netstat does not give any hint of UF trying to open port 9997&lt;BR /&gt;
8.  Does netstat show the indexer listening on port 9997? – Indexer is not listening on port 9997&lt;/P&gt;

&lt;P&gt;Can you please help me how to proceed with this issue ..&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 08:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381358#M68788</guid>
      <dc:creator>partix2</dc:creator>
      <dc:date>2019-02-14T08:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381359#M68789</link>
      <description>&lt;P&gt;So 7 &amp;amp; 8 appear to be the most concerning then.&lt;/P&gt;

&lt;P&gt;netstat -nab should show you the ports that splunk has opened. &lt;BR /&gt;
On a UF, I would expect to see (unless you have disabled) it listening on 8089.&lt;BR /&gt;
If it was trying to forward events to an indexer you should see the indexer IP and a listing for 9997&lt;/P&gt;

&lt;P&gt;On the indexer you would see it listening on 8000, 8089, and 9997 (among others) &lt;BR /&gt;
If you still don't see any ports open, are you sure that the services are running properly?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 14:26:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381359#M68789</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-02-14T14:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381360#M68790</link>
      <description>&lt;P&gt;Hi , my comments are as below : &lt;/P&gt;

&lt;P&gt;On indexer , I can see the established connection between  indexer and forwarder on port 9997.&lt;/P&gt;

&lt;P&gt;On forwarder I can see “TCP    172.31.37.196:49166    172.31.88.99:9997      FIN_WAIT_1” , its not showing as established or listening on port 9997, also logs are not forwarded to indexer. I also restarted the service on forwarder , but same result. What can be the probable reason for the same?&lt;BR /&gt;
 172.31.37.196- forwarder IP&lt;BR /&gt;
172.31.88.99 - Indexer IP&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381360#M68790</guid>
      <dc:creator>partix2</dc:creator>
      <dc:date>2020-09-29T23:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381361#M68791</link>
      <description>&lt;P&gt;Have you configured inputs.conf?&lt;/P&gt;

&lt;P&gt;Try searching for something like:&lt;BR /&gt;
&lt;CODE&gt;index=_internal |stats count by host&lt;/CODE&gt;&lt;BR /&gt;
If you see two hosts returned by that search, then Splunk is working properly but it sounds like you just need to configure the universal forwarder to collect the logs.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 14:42:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381361#M68791</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-02-15T14:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381362#M68792</link>
      <description>&lt;P&gt;Thanks for your valuable suggesstion&lt;BR /&gt;
I tried searching with the command :&lt;BR /&gt;
"index=_internal |stats count by host"&lt;/P&gt;

&lt;P&gt;This was successful as I was getting logs from that forwarder but when I am simply searching with only the hostname of the Forwarder it shows no results.&lt;/P&gt;

&lt;P&gt;May I know the reason for that?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 12:41:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381362#M68792</guid>
      <dc:creator>partix2</dc:creator>
      <dc:date>2019-02-18T12:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder issue in AWS</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381363#M68793</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have one more problem, I am only able to see the logs from my folder on universal forwarder:&lt;/P&gt;

&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk&lt;/P&gt;

&lt;P&gt;Apart from it am not able to see any folder logs&lt;/P&gt;

&lt;P&gt;Can you please suggest something on this?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Feb 2019 12:47:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forwarder-issue-in-AWS/m-p/381363#M68793</guid>
      <dc:creator>partix2</dc:creator>
      <dc:date>2019-02-20T12:47:49Z</dc:date>
    </item>
  </channel>
</rss>

