<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder  is active - indexer no data in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445391#M77516</link>
    <description>&lt;P&gt;Hello and thanks for the reply&lt;/P&gt;

&lt;P&gt;I checked the logs but found no problems there.&lt;BR /&gt;
I changed the outputs.conf per your suggestion, restarted the forwarder, and indexer, but&lt;BR /&gt;
no luck.&lt;/P&gt;

&lt;P&gt;any other suggestions?&lt;/P&gt;

&lt;P&gt;thanks again&lt;/P&gt;

&lt;P&gt;eholz1&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jun 2019 21:17:45 GMT</pubDate>
    <dc:creator>eholz1</dc:creator>
    <dc:date>2019-06-28T21:17:45Z</dc:date>
    <item>
      <title>Forwarder  is active - indexer no data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445389#M77514</link>
      <description>&lt;P&gt;Forgive me for bringing this up. The problem is forwarding and receiving.&lt;BR /&gt;
At one time I had this working. Now, nothing works.&lt;BR /&gt;
I have a universal forwarder installed on a red hat linux ver 7.6 server.&lt;BR /&gt;
&lt;STRONG&gt;The outputs file is:&lt;/STRONG&gt;&lt;BR /&gt;
[tcpout]&lt;BR /&gt;
defaultGroup=net_files&lt;BR /&gt;
[tcpout:net_idx]&lt;BR /&gt;
server=10.48.11.67:9997&lt;/P&gt;

&lt;P&gt;the list forwarder command indicates these values as active forwards&lt;BR /&gt;
I have my indexer set to "listen" on data input:  "Local Inputs" - TCP, and port 9997&lt;BR /&gt;
With this configuration I get only "cooked" data - no data from the files I am monitoring&lt;BR /&gt;
These files show correctly in the "splunk list monitor" cli command on the universal forwarder&lt;/P&gt;

&lt;P&gt;The inputs.conf file on receiver/indexer:&lt;BR /&gt;
[default]&lt;BR /&gt;
[splunktcp://9997]&lt;BR /&gt;
disabled = 0&lt;/P&gt;

&lt;P&gt;I have restarted the forwarder,indexer, and syslog-ng (which forwards the data)&lt;BR /&gt;
One of the files I monitor is updated every 30 sec or so, so that data should be transferred to the indexer, it is not.&lt;/P&gt;

&lt;P&gt;Do you have any idea on how to resolve this issue? I am baffled as a week ago it was all working fine.&lt;BR /&gt;
The only change I tried was forwarding the same data to a different indexer.&lt;/P&gt;

&lt;P&gt;I am open to suggestions,&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Eholz1&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:04:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445389#M77514</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2020-09-30T01:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder  is active - indexer no data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445390#M77515</link>
      <description>&lt;P&gt;Check your internal logs for any errors in TcpOutputProc on forwarders and TcpInputProc on indexers.&lt;/P&gt;

&lt;P&gt;I suspect the issue is in your outputs stanza. Try changing the net_files to net_idx. &lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:04:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445390#M77515</guid>
      <dc:creator>alanzchan</dc:creator>
      <dc:date>2020-09-30T01:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder  is active - indexer no data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445391#M77516</link>
      <description>&lt;P&gt;Hello and thanks for the reply&lt;/P&gt;

&lt;P&gt;I checked the logs but found no problems there.&lt;BR /&gt;
I changed the outputs.conf per your suggestion, restarted the forwarder, and indexer, but&lt;BR /&gt;
no luck.&lt;/P&gt;

&lt;P&gt;any other suggestions?&lt;/P&gt;

&lt;P&gt;thanks again&lt;/P&gt;

&lt;P&gt;eholz1&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 21:17:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445391#M77516</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-06-28T21:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder  is active - indexer no data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445392#M77517</link>
      <description>&lt;P&gt;I’m guessing that solved your problem since you accepted my answer. If not, check this out: &lt;A href="https://answers.splunk.com/answers/696093/what-are-the-basic-troubleshooting-steps-in-case-o.html"&gt;https://answers.splunk.com/answers/696093/what-are-the-basic-troubleshooting-steps-in-case-o.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 23:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445392#M77517</guid>
      <dc:creator>alanzchan</dc:creator>
      <dc:date>2019-06-28T23:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder  is active - indexer no data</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445393#M77518</link>
      <description>&lt;P&gt;Yes, but thanks for the link above, it is very helpful&lt;/P&gt;

&lt;P&gt;eholz1&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 17:13:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-active-indexer-no-data/m-p/445393#M77518</guid>
      <dc:creator>eholz1</dc:creator>
      <dc:date>2019-07-01T17:13:50Z</dc:date>
    </item>
  </channel>
</rss>

