<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configured but inactive forwards in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381520#M68810</link>
    <description>&lt;P&gt;Did you restart your splunkforwarder service after the configuration?&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2019 02:26:51 GMT</pubDate>
    <dc:creator>natalienguyen</dc:creator>
    <dc:date>2019-07-09T02:26:51Z</dc:date>
    <item>
      <title>Configured but inactive forwards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381518#M68808</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;/P&gt;

&lt;P&gt;i'm in doubt, i have installed UF on windows server but when i list forward-server it says that there are no active fordware but is configurated, on port 9997 and also de deploy with 8088. What issue do you think it is? is there a way to active the forwarder? &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 23:19:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381518#M68808</guid>
      <dc:creator>julian0125</dc:creator>
      <dc:date>2019-07-08T23:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Configured but inactive forwards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381519#M68809</link>
      <description>&lt;P&gt;Yup - you need to start it, probably as a service. &lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 00:16:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381519#M68809</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2019-07-09T00:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Configured but inactive forwards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381520#M68810</link>
      <description>&lt;P&gt;Did you restart your splunkforwarder service after the configuration?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 02:26:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381520#M68810</guid>
      <dc:creator>natalienguyen</dc:creator>
      <dc:date>2019-07-09T02:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Configured but inactive forwards</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381521#M68811</link>
      <description>&lt;P&gt;Hi  julian0125,&lt;BR /&gt;
did you checked if the connection ports are open? you can check them using telnet.&lt;BR /&gt;
then, you can check in forwarder's logs (&lt;CODE&gt;$SPLUNK_HOME/var/log/splunk/&lt;/CODE&gt;) if the connection is established.&lt;BR /&gt;
At least check if the forwarder is active, you can check the process (&lt;CODE&gt;ps -eafd&lt;/CODE&gt;) searching for &lt;CODE&gt;splunkd&lt;/CODE&gt; process.&lt;BR /&gt;
If you find that the process is active and ports are open, check if the servername is correct (&lt;CODE&gt;$SPLUNK_HOME/etc/system/local/server.conf&lt;/CODE&gt; e &lt;CODE&gt;$SPLUNK_HOME/etc/system/local/inputs.conf&lt;/CODE&gt;).&lt;/P&gt;

&lt;P&gt;You can see at &lt;A href="https://docs.splunk.com/Documentation/Forwarder/7.3.0/Forwarder/Troubleshoottheuniversalforwarder"&gt;https://docs.splunk.com/Documentation/Forwarder/7.3.0/Forwarder/Troubleshoottheuniversalforwarder&lt;/A&gt; or &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Receiverconnection"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Receiverconnection&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 06:27:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configured-but-inactive-forwards/m-p/381521#M68811</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2019-07-09T06:27:14Z</dc:date>
    </item>
  </channel>
</rss>

