<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure Universal Forwarder on my personal machine where Splunk Enterprise is installed for learning purpose? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Universal-Forwarder-on-my-personal-machine/m-p/388743#M69591</link>
    <description>&lt;P&gt;Please share your inputs.conf and outputs.conf.&lt;/P&gt;

&lt;P&gt;Also check if firewall is blocking any ports please.&lt;/P&gt;</description>
    <pubDate>Fri, 11 May 2018 12:08:12 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2018-05-11T12:08:12Z</dc:date>
    <item>
      <title>How to configure Universal Forwarder on my personal machine where Splunk Enterprise is installed for learning purpose?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Universal-Forwarder-on-my-personal-machine/m-p/388742#M69590</link>
      <description>&lt;P&gt;I installed Splunk Universal Fwd and Splunk Enterprise on my C drive. I created a sample file and modified the inputs.conf as mentioned in one of the ans(link given below) and enabled the receiver by setting port to 9997. Do we have to modify/create outputs.conf file? I tried creating outputs.conf too..but no use. In outputs.conf I gave the server name as localhost and port as 9997. Am I missing something? Also, do we have to modify anything in distributed search? I assume my Splunk Enterprise is acting both as SH and Indexer.&lt;BR /&gt;
Have referred to below ans but didnt got the answer&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/490343/how-to-properly-configure-universal-forwarder-loca.html#answer-656030"&gt;https://answers.splunk.com/answers/490343/how-to-properly-configure-universal-forwarder-loca.html#answer-656030&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 10:40:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Universal-Forwarder-on-my-personal-machine/m-p/388742#M69590</guid>
      <dc:creator>ashishmaind2499</dc:creator>
      <dc:date>2018-05-11T10:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Universal Forwarder on my personal machine where Splunk Enterprise is installed for learning purpose?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Universal-Forwarder-on-my-personal-machine/m-p/388743#M69591</link>
      <description>&lt;P&gt;Please share your inputs.conf and outputs.conf.&lt;/P&gt;

&lt;P&gt;Also check if firewall is blocking any ports please.&lt;/P&gt;</description>
      <pubDate>Fri, 11 May 2018 12:08:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Universal-Forwarder-on-my-personal-machine/m-p/388743#M69591</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-05-11T12:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure Universal Forwarder on my personal machine where Splunk Enterprise is installed for learning purpose?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Universal-Forwarder-on-my-personal-machine/m-p/388744#M69592</link>
      <description>&lt;P&gt;If you're running both on the same system, you might run into trouble because, by default, both want to listen on TCP 9997.&lt;BR /&gt;
Check if both instances actually run, you might have to change the splunkd port of the UF using server.conf.&lt;/P&gt;</description>
      <pubDate>Sat, 12 May 2018 13:34:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-Universal-Forwarder-on-my-personal-machine/m-p/388744#M69592</guid>
      <dc:creator>xpac</dc:creator>
      <dc:date>2018-05-12T13:34:44Z</dc:date>
    </item>
  </channel>
</rss>

