<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406161#M72049</link>
    <description>&lt;P&gt;Did you enable receiving of data from forwarders? Check if your Splunk Enterprise instance is listening at localhost:8000/fr-FR/manager/launcher/data/inputs/tcp/cooked&lt;/P&gt;</description>
    <pubDate>Sat, 11 Aug 2018 15:56:22 GMT</pubDate>
    <dc:creator>dauren_akilbeko</dc:creator>
    <dc:date>2018-08-11T15:56:22Z</dc:date>
    <item>
      <title>please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406160#M72048</link>
      <description>&lt;P&gt;hey please help!! i did all the steps of universal forwarder configuration but i still can't forward data into splunk entreprise&lt;BR /&gt;
How CAN I configurate splunk enterprise so it could see the forwarder ??&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5553i2BCDEDB9D655D224/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;BR /&gt;
 &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5554iB02891576E6533B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 15:50:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406160#M72048</guid>
      <dc:creator>neermine</dc:creator>
      <dc:date>2018-08-11T15:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406161#M72049</link>
      <description>&lt;P&gt;Did you enable receiving of data from forwarders? Check if your Splunk Enterprise instance is listening at localhost:8000/fr-FR/manager/launcher/data/inputs/tcp/cooked&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 15:56:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406161#M72049</guid>
      <dc:creator>dauren_akilbeko</dc:creator>
      <dc:date>2018-08-11T15:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406162#M72050</link>
      <description>&lt;P&gt;i did enable receiving of data from forwaders but splunk enterprise id not listening at localhost:8000 his etat is :wait-time what can i do ?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 16:19:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406162#M72050</guid>
      <dc:creator>neermine</dc:creator>
      <dc:date>2018-08-11T16:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406163#M72051</link>
      <description>&lt;P&gt;By default Splunk listens for data from forwarders on port 9997, but you have to enable it. &lt;A href="http://i.imgur.com/pUgpVoX.png"&gt;http://i.imgur.com/pUgpVoX.png&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;8000 is for web access.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 16:23:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406163#M72051</guid>
      <dc:creator>dauren_akilbeko</dc:creator>
      <dc:date>2018-08-11T16:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406164#M72052</link>
      <description>&lt;P&gt;So you've confirmed your indexer is listening to the forwarder on port 9997. Next you have to confirm if you placed an &lt;CODE&gt;outputs.conf&lt;/CODE&gt; on the forwarder which tells the forwarder where to send the logs to. Next you should place an &lt;CODE&gt;inputs.conf&lt;/CODE&gt; on the forwarder which tell it which directory/file(s) to monitor and forwarder to Splunk. Once you add these files to the forwarder, you should then restart the Splunk service on the forwarder and do a search to verify the logs are going to Splunk.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Forwarder/7.1.2/Forwarder/Configureforwardingwithoutputs.conf"&gt;http://docs.splunk.com/Documentation/Forwarder/7.1.2/Forwarder/Configureforwardingwithoutputs.conf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorfilesanddirectorieswithinputs.conf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Aug 2018 17:12:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406164#M72052</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-08-11T17:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406165#M72053</link>
      <description>&lt;P&gt;i did all the steps that you did mention but it still does not work &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;BR /&gt;
i install the splunk entreprise on a windows 7  machine and the forwarder on another windows 7 but in the same virtuelle machine and the two system have the same ip adresse could this be the problem ? &lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 10:13:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406165#M72053</guid>
      <dc:creator>neermine</dc:creator>
      <dc:date>2018-08-13T10:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406166#M72054</link>
      <description>&lt;P&gt;it's active&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 10:14:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406166#M72054</guid>
      <dc:creator>neermine</dc:creator>
      <dc:date>2018-08-13T10:14:36Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406167#M72055</link>
      <description>&lt;P&gt;the firewall is desactivate also&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 10:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406167#M72055</guid>
      <dc:creator>neermine</dc:creator>
      <dc:date>2018-08-13T10:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406168#M72056</link>
      <description>&lt;P&gt;Did you restart the forwarder service after applying the configs? Can you do a telnet from the forwarder to the indexer to confirm you can connect. Is your indexer listening on port 9997 for active connections?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2018 14:07:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406168#M72056</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-08-13T14:07:26Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406169#M72057</link>
      <description>&lt;P&gt;it was a problem of network because the tow machines where the forwarder and the splunk were set up now i can see my machine name in the host list of splunk but i can't find the index and the sourcetype that i have create in the inputs.conf&lt;BR /&gt;
thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:28:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406169#M72057</guid>
      <dc:creator>neermine</dc:creator>
      <dc:date>2018-08-15T13:28:45Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406170#M72058</link>
      <description>&lt;P&gt;What index did you specify in your &lt;CODE&gt;inputs.conf&lt;/CODE&gt;? You can do a quick search over the tsidx files to locate your logs&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| metasearch index=*&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:32:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406170#M72058</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2018-08-15T13:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: please help me : How CAN I configurate splunk enterprise so it could see the forwarder ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406171#M72059</link>
      <description>&lt;P&gt;this is my inputs :&lt;BR /&gt;
[monitor://C:\var\log*.log]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
sourcetype = log&lt;BR /&gt;
index = me&lt;BR /&gt;
metasearch index=* didn't work&lt;BR /&gt;
my os is wondows&lt;/P&gt;</description>
      <pubDate>Wed, 15 Aug 2018 13:41:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/please-help-me-How-CAN-I-configurate-splunk-enterprise-so-it/m-p/406171#M72059</guid>
      <dc:creator>neermine</dc:creator>
      <dc:date>2018-08-15T13:41:18Z</dc:date>
    </item>
  </channel>
</rss>

