<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal forward installed on windows server but can't get the logs for that server. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405267#M71954</link>
    <description>&lt;P&gt;This page can help - &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/Cantfinddata"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 21 May 2018 17:09:10 GMT</pubDate>
    <dc:creator>ddrillic</dc:creator>
    <dc:date>2018-05-21T17:09:10Z</dc:date>
    <item>
      <title>Universal forward installed on windows server but can't get the logs for that server.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405265#M71952</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;I am testing universal forwarding in our testing environment and also installed universal forwarder in one of windows server, but can't get the desire logs. &lt;BR /&gt;
My test environment included Splunk Enterprise OVA as server and Windows server (with universal forwarder installed) which is client. I had used the "deployment server" command(set deploy-poll) and then restart.&lt;/P&gt;

&lt;P&gt;On Splunk OVA enterprise server&lt;/P&gt;

&lt;P&gt;Added forwarder input using Settings -&amp;gt; "Data Inputs" -&amp;gt; "Forwarded Inputs" -&amp;gt; "Windows Event Logs"-&amp;gt; New (could see my desired deployment client in the list). Selected Application, security &amp;amp; system events.&lt;/P&gt;

&lt;P&gt;Tested:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;I had check the Eventviewer logs; there logs are generating&lt;/LI&gt;
&lt;LI&gt;Check the Tcp dump; there is also logs are coming from the windows server.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Also I am geeting Messages:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Skipped indexing of internal audits event will keep dropping events until indexer congestion is remedied.check disk space and other issues that may cause indexer to block. &lt;/LI&gt;
&lt;LI&gt;Forwarding the indexer group default-autolb-group blocked for 10 seconds.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 21 May 2018 13:15:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405265#M71952</guid>
      <dc:creator>Sagar0511</dc:creator>
      <dc:date>2018-05-21T13:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forward installed on windows server but can't get the logs for that server.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405266#M71953</link>
      <description>&lt;P&gt;Hi Sarag0511, I believe the issue is that, along with the input for the forwarder, you'll have to create an output that sends the events to the indexer.&lt;/P&gt;

&lt;P&gt;The indexer will need to have a network input, and also the have the same index names specified in the input config on the forwarder.&lt;/P&gt;

&lt;P&gt;This page has some commands that can be run on the forwarder to setup the config : &lt;A href="http://docs.splunk.com/Documentation/Forwarder/7.1.0/Forwarder/Configuretheuniversalforwarder#Configure_the_universal_forwarder_to_connect_to_a_receiving_indexer"&gt;http://docs.splunk.com/Documentation/Forwarder/7.1.0/Forwarder/Configuretheuniversalforwarder#Configure_the_universal_forwarder_to_connect_to_a_receiving_indexer&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Please let me know if this helps!&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 13:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405266#M71953</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2018-05-21T13:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forward installed on windows server but can't get the logs for that server.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405267#M71954</link>
      <description>&lt;P&gt;This page can help - &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.3/Troubleshooting/Cantfinddata"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 May 2018 17:09:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405267#M71954</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-05-21T17:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forward installed on windows server but can't get the logs for that server.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405268#M71955</link>
      <description>&lt;P&gt;Hi Sagar0511,&lt;BR /&gt;
at first you have to enable Forwarders receiving [Settings -- Forward and Receiving -- Receiving]&lt;/P&gt;

&lt;P&gt;Then you have to configure on your Forwarder the indexer to send logs:&lt;BR /&gt;
you can do this directly on Forwarder (only for test) running a command on the Forwarder by CLI&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cd \Program Files\splunkuniversalforwarder\bin
splunk add forward-server &amp;lt;host name or ip address&amp;gt;:&amp;lt;listening port&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Or deploying a Technical Add-On (TA) that contains outputs.conf file using Deployment Server.&lt;/P&gt;

&lt;P&gt;Then you have to say to the Forwarder which logs you want to send to indexer.&lt;BR /&gt;
To do this you can download a TA from SplunkBase (Splunk_TA_Windows) and then deploy it  using Deployment Server.&lt;BR /&gt;
Or, for a test, you can copy it (after two untar) on Forwarder $SPLUNK_HOME\etc\apps folder&lt;/P&gt;

&lt;P&gt;You can also follow the process described at &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.0/Data/Getstartedwithgettingdatain" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.0/Data/Getstartedwithgettingdatain&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:39:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-forward-installed-on-windows-server-but-can-t-get-the/m-p/405268#M71955</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-29T19:39:31Z</dc:date>
    </item>
  </channel>
</rss>

