<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarder - inactive problem in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43947#M8206</link>
    <description>&lt;P&gt;You're having a UniversalForwarder and want to send data to another forwarder "HeavyForwarder" right? The command &lt;CODE&gt;splunk list forward-servers&lt;/CODE&gt; shows you only, if the connection from UniversalForwarder to "HeavyForwarder" has been established. In this case there is no established connection - HeavyForwarder does not accept input from your UniversalForwarder!&lt;/P&gt;

&lt;P&gt;Make sure you've setup receiving on server 10.251.1.1 (incl. listening on port 6996) correctly. While starting up your UniversalForwarder open on both (UniversalForwarder &amp;amp; HeavyForwarder) servers the logfiles -&amp;gt; &lt;CODE&gt;$SPLUNK_HOME/var/log/splunkd.log&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;What does the log telling you?&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jan 2012 08:06:30 GMT</pubDate>
    <dc:creator>LCM</dc:creator>
    <dc:date>2012-01-05T08:06:30Z</dc:date>
    <item>
      <title>forwarder - inactive problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43946#M8205</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I have just started to implement splunk in my network. I have few servers, but I would like to start with Unix machines.&lt;/P&gt;

&lt;P&gt;I have donwloaded and installed main server and it looks fine.&lt;/P&gt;

&lt;P&gt;The problem starts when it goes to forwarder...&lt;/P&gt;

&lt;P&gt;I have updated following file:&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/outputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
maxQueueSize = 500KB
indexAndForward=true

[tcpout:fastlane]
server = 10.251.1.1:6996
sendCookedData = false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When I put command:  &lt;CODE&gt;/opt/splunkforwarder/bin/splunk list forward-server&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Active forwards:
        None
Configured but inactive forwards:
        10.251.1.1:6996
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;How do I enable this forward mode ??&lt;/P&gt;

&lt;P&gt;I have also tried:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[splunk@CentOS01 splunkforwarder]$ /opt/splunkforwarder/bin/splunk enable app SplunkLightForwarder
In handler 'localapps': Application does not exist: SplunkLightForwarder
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help from you would be nice &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2012 09:46:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43946#M8205</guid>
      <dc:creator>levisik</dc:creator>
      <dc:date>2012-01-04T09:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder - inactive problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43947#M8206</link>
      <description>&lt;P&gt;You're having a UniversalForwarder and want to send data to another forwarder "HeavyForwarder" right? The command &lt;CODE&gt;splunk list forward-servers&lt;/CODE&gt; shows you only, if the connection from UniversalForwarder to "HeavyForwarder" has been established. In this case there is no established connection - HeavyForwarder does not accept input from your UniversalForwarder!&lt;/P&gt;

&lt;P&gt;Make sure you've setup receiving on server 10.251.1.1 (incl. listening on port 6996) correctly. While starting up your UniversalForwarder open on both (UniversalForwarder &amp;amp; HeavyForwarder) servers the logfiles -&amp;gt; &lt;CODE&gt;$SPLUNK_HOME/var/log/splunkd.log&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;What does the log telling you?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2012 08:06:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43947#M8206</guid>
      <dc:creator>LCM</dc:creator>
      <dc:date>2012-01-05T08:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder - inactive problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43948#M8207</link>
      <description>&lt;P&gt;qf@qan0030:~&amp;gt; /opt/splunkforwarder/bin/splunk list forward-server&lt;BR /&gt;
Active forwards:&lt;BR /&gt;
        None&lt;BR /&gt;
Configured but inactive forwards:&lt;BR /&gt;
        sdvl5qtm001.td.teradata.com:8089&lt;BR /&gt;
        sdvl5qtm001:9997&lt;/P&gt;

&lt;P&gt;I am also seeing the same problem, Please help me out how to resolve this issue.&lt;/P&gt;

&lt;P&gt;my active forwards are none.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2015 12:02:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43948#M8207</guid>
      <dc:creator>sobhitakumarsah</dc:creator>
      <dc:date>2015-04-24T12:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder - inactive problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43949#M8208</link>
      <description>&lt;P&gt;This is iptables rules problem I solved it by running following command ;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 9997 -m comment --comment "splunk remote Listener" -j ACCEPT 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Refer &lt;A href="https://answers.splunk.com/answers/27070/forward-server-listed-as-inactive.html"&gt;this page&lt;/A&gt;  for more&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2018 21:04:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43949#M8208</guid>
      <dc:creator>ss026381</dc:creator>
      <dc:date>2018-02-02T21:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder - inactive problem</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43950#M8209</link>
      <description>&lt;P&gt;Did you enable receiving on the indexer?  Splunk doesn't listen for forwarded inputs by default.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/Enableareceiver"&gt;https://docs.splunk.com/Documentation/Forwarder/7.0.1/Forwarder/Enableareceiver&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Feb 2018 02:43:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-inactive-problem/m-p/43950#M8209</guid>
      <dc:creator>micahkemp</dc:creator>
      <dc:date>2018-02-03T02:43:08Z</dc:date>
    </item>
  </channel>
</rss>

