<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder Syntax for Inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42492#M7919</link>
    <description>&lt;P&gt;I am not sure if it's typo in your post but the syntax should be:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://c:\program files\syslogd\logs]
disabled=false
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 03 May 2012 06:34:39 GMT</pubDate>
    <dc:creator>MarioM</dc:creator>
    <dc:date>2012-05-03T06:34:39Z</dc:date>
    <item>
      <title>Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42491#M7918</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I am new to Splunk and have just configured a universal forwarder on a remote windows server in order to forward all log files under a specified folder to the receiver&lt;/P&gt;

&lt;P&gt;However I am not able to see the logs being piped to the receiver.&lt;/P&gt;

&lt;P&gt;My settings for "inputs.conf" as follows:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Monitor://\\program files\syslogd\logs] 

 Disable=0
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help is appreciated&lt;/P&gt;

&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 06:22:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42491#M7918</guid>
      <dc:creator>fongkh76</dc:creator>
      <dc:date>2012-05-03T06:22:37Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42492#M7919</link>
      <description>&lt;P&gt;I am not sure if it's typo in your post but the syntax should be:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://c:\program files\syslogd\logs]
disabled=false
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 03 May 2012 06:34:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42492#M7919</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-05-03T06:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42493#M7920</link>
      <description>&lt;P&gt;Make sure your outputs.conf is correctly configured, as well. &lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 08:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42493#M7920</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-05-03T08:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42494#M7921</link>
      <description>&lt;P&gt;Thank you so much. It worked perfect with your advised syntax&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 08:47:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42494#M7921</guid>
      <dc:creator>fongkh76</dc:creator>
      <dc:date>2012-05-03T08:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42495#M7922</link>
      <description>&lt;P&gt;you welcome! then accept the answer for others looking at same issue,thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 09:01:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42495#M7922</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-05-03T09:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42496#M7923</link>
      <description>&lt;P&gt;how do i accept the answer ?&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 09:13:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42496#M7923</guid>
      <dc:creator>fongkh76</dc:creator>
      <dc:date>2012-05-03T09:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42497#M7924</link>
      <description>&lt;P&gt;on the left side of the answer and below the answer (before comments)&lt;/P&gt;</description>
      <pubDate>Thu, 03 May 2012 09:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42497#M7924</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-05-03T09:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42498#M7925</link>
      <description>&lt;P&gt;Splunk.com&lt;BR /&gt;
Documentation&lt;BR /&gt;
Splunkbase&lt;BR /&gt;
Answers&lt;BR /&gt;
Wiki&lt;BR /&gt;
Blogs&lt;BR /&gt;
Developers&lt;/P&gt;

&lt;P&gt;Sign UpLogin FAQ&lt;/P&gt;

&lt;P&gt;HomeAnswersAppsuserstagsbadgesask a questionupload an app&lt;/P&gt;

&lt;P&gt;Universal Forwarder Syntax for Inputs.conf&lt;/P&gt;

&lt;P&gt;0 &lt;/P&gt;

&lt;P&gt;Hi, I am new to Splunk and have just configured a universal forwarder on a remote windows server in order to forward all log files under a specified folder to the receiver However I am not able to see the logs being piped to the receiver. My settings for "inputs.conf" as follows: [Monitor://\program files\syslogd\logs]&lt;/P&gt;

&lt;P&gt;Disable=0&lt;BR /&gt;
 Any help is appreciated Thank you&lt;BR /&gt;
inputsconf&lt;/P&gt;

&lt;P&gt;asked 02 May '12, 23:22&lt;/P&gt;

&lt;P&gt;fongkh76&lt;BR /&gt;
11&lt;BR /&gt;
accept rate:0%&lt;/P&gt;

&lt;P&gt;edited 02 May '12, 23:40&lt;/P&gt;

&lt;P&gt;Ayn&lt;BR /&gt;
24.7k●3●7●17&lt;/P&gt;

&lt;P&gt;Make sure your outputs.conf is correctly configured, as well.  /k&lt;BR /&gt;
(03 May '12, 01:08)kristian.kolb&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;One Answer:&lt;/P&gt;

&lt;P&gt;oldestnewestmost voted&lt;/P&gt;

&lt;P&gt;0 &lt;/P&gt;

&lt;P&gt;I am not sure if it's typo in your post but the syntax should be: [monitor://c:\program files\syslogd\logs]&lt;BR /&gt;
disabled=false&lt;/P&gt;

&lt;P&gt;link&lt;/P&gt;

&lt;P&gt;answered 02 May '12, 23:34&lt;/P&gt;

&lt;P&gt;MarioM&lt;BR /&gt;
2.7k●4●7&lt;BR /&gt;
accept rate:20%&lt;/P&gt;

&lt;P&gt;Thank you so much. It worked perfect with your advised syntax&lt;BR /&gt;
(03 May '12, 01:47)fongkh76&lt;/P&gt;

&lt;P&gt;you welcome! then accept the answer for others looking at same issue,thanks!&lt;BR /&gt;
(03 May '12, 02:01)MarioM&lt;/P&gt;

&lt;P&gt;how do i accept the answer ?&lt;BR /&gt;
(03 May '12, 02:13)fongkh76&lt;/P&gt;

&lt;P&gt;on the left side of the answer and below the answer (before comments)&lt;BR /&gt;
(03 May '12, 02:52)MarioM&lt;/P&gt;

&lt;P&gt;Post your answer&lt;/P&gt;

&lt;P&gt;Same problem; logs not being forwarded from a Windows server to pair of indexers. See configs below. A restart of a service "InterraBaton" on the monitored server does not show up on the Splunk via the search head but does show up in the logs on the IB server. Any ideas would b appreciated.&lt;/P&gt;

&lt;H6&gt;inputs.conf&lt;/H6&gt;

&lt;P&gt;[default]&lt;BR /&gt;
index         = default&lt;BR /&gt;
_rcvbuf        = 1572864&lt;BR /&gt;
host = DDCIBVERMGR02&lt;BR /&gt;
evt_resolve_ad_obj = 0&lt;BR /&gt;
evt_dc_name=&lt;BR /&gt;
evt_dns_name=&lt;/P&gt;

&lt;P&gt;.&lt;BR /&gt;
.&lt;BR /&gt;
.&lt;/P&gt;

&lt;P&gt;[monitor://C:\batonSites\VerificationManager\log]    &amp;lt;&amp;lt;&amp;lt; log 1&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
[monitor://C:\batonSites\Workers\log]               &amp;lt;&amp;lt;&amp;lt; log 2&lt;BR /&gt;
disabled = 1&lt;/P&gt;

&lt;H6&gt;outputs.conf&lt;/H6&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
maxQueueSize = 500KB&lt;BR /&gt;
forwardedindex.0.whitelist = .*&lt;BR /&gt;
forwardedindex.1.blacklist = _.*&lt;BR /&gt;
forwardedindex.2.whitelist = _audit&lt;BR /&gt;
forwardedindex.filter.disable = false&lt;BR /&gt;
indexAndForward = false&lt;BR /&gt;
autoLBFrequency = 30&lt;BR /&gt;
blockOnCloning = true&lt;BR /&gt;
compressed = false&lt;BR /&gt;
disabled = false&lt;BR /&gt;
dropClonedEventsOnQueueFull = 5&lt;BR /&gt;
dropEventsOnQueueFull = -1&lt;BR /&gt;
heartbeatFrequency = 30&lt;BR /&gt;
maxFailuresPerInterval = 2&lt;BR /&gt;
secsInFailureInterval = 1&lt;BR /&gt;
maxConnectionsPerIndexer = 2&lt;BR /&gt;
forceTimebasedAutoLB = false&lt;BR /&gt;
sendCookedData = true&lt;BR /&gt;
connectionTimeout = 20 &lt;BR /&gt;
readTimeout = 300&lt;BR /&gt;
writeTimeout = 300 &lt;BR /&gt;
useACK = true&lt;/P&gt;

&lt;P&gt;defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;
server = XXX.YYY.138.158:9997,XXX.YYY.138.159:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://XXX.YYY.138.158:9997]&lt;/P&gt;

&lt;P&gt;[hide preview]&lt;/P&gt;

&lt;P&gt;1324 characters / 164 words&lt;/P&gt;

&lt;P&gt;Same problem; logs not being forwarded from a Windows server to pair of indexers. See configs below. A restart of a service "InterraBaton" on the monitored server does not show up on the Splunk via the search head but does show up in the logs on the IB server. Any ideas would b appreciated.&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;P&gt;[default] index = default rcvbuf = 1572864 host = DDCIBVERMGR02 evtresolveadobj = 0 evtdcname= evtdnsname=&lt;/P&gt;

&lt;P&gt;. . .&lt;/P&gt;

&lt;P&gt;[monitor://C:\batonSites\VerificationManager\log] &amp;lt;&amp;lt;&amp;lt; log 1 disabled = 1 [monitor://C:\batonSites\Workers\log] &amp;lt;&amp;lt;&amp;lt; log 2 disabled = 1&lt;/P&gt;

&lt;P&gt;outputs.conf&lt;/P&gt;

&lt;P&gt;[tcpout] maxQueueSize = 500KB forwardedindex.0.whitelist = .* forwardedindex.1.blacklist = _.* forwardedindex.2.whitelist = _audit forwardedindex.filter.disable = false indexAndForward = false autoLBFrequency = 30 blockOnCloning = true compressed = false disabled = false dropClonedEventsOnQueueFull = 5 dropEventsOnQueueFull = -1 heartbeatFrequency = 30 maxFailuresPerInterval = 2 secsInFailureInterval = 1 maxConnectionsPerIndexer = 2 forceTimebasedAutoLB = false sendCookedData = true connectionTimeout = 20 readTimeout = 300 writeTimeout = 300 useACK = true&lt;/P&gt;

&lt;P&gt;defaultGroup = default-autolb-group&lt;/P&gt;

&lt;P&gt;[tcpout:default-autolb-group] server = XXX.YYY.138.158:9997,XXX.YYY.138.159:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://XXX.YYY.138.158:9997]&lt;/P&gt;

&lt;P&gt;Privacy &amp;amp; Terms &lt;/P&gt;

&lt;P&gt;0&lt;BR /&gt;
inShare.&lt;/P&gt;

&lt;P&gt;Follow this question&lt;BR /&gt;
Email:&lt;BR /&gt;
Log In to enable email subscriptions&lt;BR /&gt;
RSS:&lt;BR /&gt;
 Answers&lt;/P&gt;

&lt;P&gt;Answers + Comments&lt;/P&gt;

&lt;P&gt;•&lt;BR /&gt;
•&lt;BR /&gt;
•&lt;BR /&gt;
•&lt;BR /&gt;
•&lt;BR /&gt;
•&lt;BR /&gt;
•&lt;/P&gt;

&lt;P&gt;Tags: &lt;/P&gt;

&lt;P&gt;inputs &lt;BR /&gt;
conf &lt;/P&gt;

&lt;P&gt;Asked: 02 May '12, 23:22&lt;/P&gt;

&lt;P&gt;Seen: 799 times&lt;/P&gt;

&lt;P&gt;Last updated: 03 May '12, 02:52&lt;/P&gt;

&lt;P&gt;Related questions&lt;/P&gt;

&lt;P&gt;Multiple index locations for forwarder&lt;/P&gt;

&lt;P&gt;Universal Forwarder&lt;/P&gt;

&lt;P&gt;Are "_meta"-entries still supported in inputs.conf?&lt;/P&gt;

&lt;P&gt;syntax for scripted input in inputs.conf&lt;/P&gt;

&lt;P&gt;How can I merge _meta from several inputs.conf files&lt;/P&gt;

&lt;P&gt;List of valid [perfmon://] stanzas for inputs.conf&lt;/P&gt;

&lt;P&gt;Splunk Universal forwarder inputs.conf&lt;/P&gt;

&lt;P&gt;How to monitor assembly folder in windows ?&lt;/P&gt;

&lt;P&gt;universal forwarder scripts linux&lt;/P&gt;

&lt;P&gt;Privacy Policy | Terms of Use | Support&lt;/P&gt;

&lt;P&gt;Copyright © 2005-2012 Splunk Inc. All rights reserved. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42498#M7925</guid>
      <dc:creator>hokie1999</dc:creator>
      <dc:date>2020-09-28T13:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder Syntax for Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42499#M7926</link>
      <description>&lt;P&gt;Correction, inputs.conf has this:&lt;/P&gt;

&lt;P&gt;[monitor://C:batonSites\VerificationManager\log]&lt;BR /&gt;
disabled = 1&lt;BR /&gt;
[monitor://C:batonSites\Workers\log]&lt;BR /&gt;
disabled = 1&lt;/P&gt;</description>
      <pubDate>Thu, 16 May 2013 16:05:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-Syntax-for-Inputs-conf/m-p/42499#M7926</guid>
      <dc:creator>hokie1999</dc:creator>
      <dc:date>2013-05-16T16:05:19Z</dc:date>
    </item>
  </channel>
</rss>

