<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows UniversalForwarder not registering Syslog input in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384722#M69167</link>
    <description>&lt;P&gt;Is Splunk running as SYSTEM or as a user and if as a user does it have the required permissions to listen to ports on Windows?&lt;/P&gt;

&lt;P&gt;Have you checked splunkd.log when it starts up for "TcpInput" type components and if there are any issues it is reporting?&lt;/P&gt;</description>
    <pubDate>Fri, 20 Jul 2018 10:33:13 GMT</pubDate>
    <dc:creator>lmaclean</dc:creator>
    <dc:date>2018-07-20T10:33:13Z</dc:date>
    <item>
      <title>Windows UniversalForwarder not registering Syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384720#M69165</link>
      <description>&lt;P&gt;I am trying to make UniversalForwarder on Windows Server 2008 R2 Standard act as a syslog data receiver and forward this data to the Indexer.&lt;BR /&gt;
It seems that Splunk on this Windows machine does not handle incoming syslog data.&lt;BR /&gt;
Below is config:&lt;BR /&gt;
&lt;EM&gt;C:\SplunkUniversalForwarder\bin&amp;gt;splunk.exe cmd btool inputs list udp&lt;BR /&gt;
[udp]&lt;BR /&gt;
_rcvbuf = 1572864&lt;BR /&gt;
connection_host = ip&lt;BR /&gt;
evt_dc_name =&lt;BR /&gt;
evt_dns_name =&lt;BR /&gt;
evt_resolve_ad_obj = 0&lt;BR /&gt;
host = Splunk-gtw&lt;BR /&gt;
index = default&lt;BR /&gt;
[udp://514]&lt;BR /&gt;
_rcvbuf = 1572864&lt;BR /&gt;
connection_host = ip&lt;BR /&gt;
evt_dc_name =&lt;BR /&gt;
evt_dns_name =&lt;BR /&gt;
evt_resolve_ad_obj = 0&lt;BR /&gt;
host = Splunk-gtw&lt;BR /&gt;
index = default&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;C:\SplunkUniversalForwarder\bin&amp;gt;netstat -apb UDP&lt;BR /&gt;
Active Connections&lt;BR /&gt;
  Proto  Local Address          Foreign Address        State&lt;BR /&gt;
  UDP    0.0.0.0:123            *:&lt;/EM&gt;&lt;BR /&gt;
  W32Time&lt;BR /&gt;
 [svchost.exe]&lt;BR /&gt;
  UDP    0.0.0.0:514            &lt;EM&gt;:&lt;/EM&gt;&lt;BR /&gt;
 [splunkd.exe]*&lt;/P&gt;

&lt;P&gt;I see data in Wireshark capture, but metrics.log shows this:&lt;BR /&gt;
&lt;EM&gt;6-15-2018 13:23:12.395 +0300 INFO  Metrics - group=queue, name=udp_queue, max_size_kb=500, current_size_kb=0, current_size=0, largest_size=0, smallest_size=0&lt;BR /&gt;
06-15-2018 13:23:12.395 +0300 INFO  Metrics - group=udpin_connections, *:514, sourcePort=514, _udp_bps=0.00, _udp_kbps=0.00, _udp_avg_thruput=0.00, _udp_kprocessed=0.00, _udp_eps=0.00&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Please advise what may be the source of the trouble&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:00:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384720#M69165</guid>
      <dc:creator>pkarpushin</dc:creator>
      <dc:date>2020-09-29T20:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Windows UniversalForwarder not registering Syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384721#M69166</link>
      <description>&lt;P&gt;Hi, did you ever resolve this issue? I am observing the same issue in my network at the moment.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 05:49:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384721#M69166</guid>
      <dc:creator>splkmika1</dc:creator>
      <dc:date>2018-07-20T05:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Windows UniversalForwarder not registering Syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384722#M69167</link>
      <description>&lt;P&gt;Is Splunk running as SYSTEM or as a user and if as a user does it have the required permissions to listen to ports on Windows?&lt;/P&gt;

&lt;P&gt;Have you checked splunkd.log when it starts up for "TcpInput" type components and if there are any issues it is reporting?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 10:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384722#M69167</guid>
      <dc:creator>lmaclean</dc:creator>
      <dc:date>2018-07-20T10:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Windows UniversalForwarder not registering Syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384723#M69168</link>
      <description>&lt;P&gt;No, unfortunately. I had to give up listening 514 udp on my Windows machine, and started monitoring log files on a remote machine instead.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 07:09:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384723#M69168</guid>
      <dc:creator>pkarpushin</dc:creator>
      <dc:date>2018-07-23T07:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Windows UniversalForwarder not registering Syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384724#M69169</link>
      <description>&lt;P&gt;no worries. Thanks. Yeah I moved over to monitoring files on a separate syslog server as well.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 00:12:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384724#M69169</guid>
      <dc:creator>splkmika1</dc:creator>
      <dc:date>2018-07-25T00:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Windows UniversalForwarder not registering Syslog input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384725#M69170</link>
      <description>&lt;P&gt;tried running it as the default Windows LocalSystem account, so the permissions I think should be ok. I could also see the Universal Forwarder exe listening on udp 514 with a netstat -a -b.&lt;/P&gt;

&lt;P&gt;I've given up on this and just gone with using an external syslog server with a Universal Forwarder installed.&lt;BR /&gt;
Thanks for your response.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2018 00:16:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-UniversalForwarder-not-registering-Syslog-input/m-p/384725#M69170</guid>
      <dc:creator>splkmika1</dc:creator>
      <dc:date>2018-07-25T00:16:09Z</dc:date>
    </item>
  </channel>
</rss>

