<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question 1: Splunk Forwarder - configured inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44625#M8364</link>
    <description>&lt;P&gt;the forwarder must be missing a configured outputs.conf, please edit to add the definition (use the other one as model) or use the CLI commands to define the forwarding.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Feb 2013 07:00:11 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2013-02-27T07:00:11Z</dc:date>
    <item>
      <title>Question 1: Splunk Forwarder - configured inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44624#M8363</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I have a standalone Splunk Server.&lt;BR /&gt;
I have setup the server to revieve data from universal forwarder on a particular port.&lt;BR /&gt;
I have setup an input on the server (index and web) in etc/system/local/inputs.conf staring with&lt;BR /&gt;
[splunktcp...&lt;/P&gt;

&lt;P&gt;One forwarder now appears to be sending logs after much fiddling around getting it to work.&lt;BR /&gt;
The second forwarder is now doing what the first one did.  It returns the following message in the logs:&lt;/P&gt;

&lt;P&gt;CMConfig - A splunktcp forwarder port is not configured in inputs.conf&lt;/P&gt;

&lt;P&gt;Which input file is this message refereing to? Forwarder or Server?&lt;/P&gt;

&lt;P&gt;As far as I can tell the inputs.conf is serup.&lt;BR /&gt;
What should I be looking at to solve this?&lt;BR /&gt;
Does it need a port per connection?&lt;/P&gt;

&lt;P&gt;We are running the latest version of splunk&lt;/P&gt;

&lt;P&gt;Thank in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 01:30:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44624#M8363</guid>
      <dc:creator>ghannemann</dc:creator>
      <dc:date>2013-02-27T01:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: Question 1: Splunk Forwarder - configured inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44625#M8364</link>
      <description>&lt;P&gt;the forwarder must be missing a configured outputs.conf, please edit to add the definition (use the other one as model) or use the CLI commands to define the forwarding.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 07:00:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44625#M8364</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2013-02-27T07:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Question 1: Splunk Forwarder - configured inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44626#M8365</link>
      <description>&lt;P&gt;This seems to almost a false message.&lt;BR /&gt;
The ouputs.conf are configured - correct according to what I can find in the documentation.&lt;BR /&gt;
The message appears nearly everytime when the forwarder is started.  It then appears to reconnect and then it works. If can see the  via netstat that an initial connection has a status for TIME_WAIT, and a second connection shows ESTABLISHED.  The forwarder then appears to work.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2013 00:17:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44626#M8365</guid>
      <dc:creator>ghannemann</dc:creator>
      <dc:date>2013-03-12T00:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question 1: Splunk Forwarder - configured inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44627#M8366</link>
      <description>&lt;P&gt;Long time ago - was a network issue&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2015 02:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-1-Splunk-Forwarder-configured-inputs-conf/m-p/44627#M8366</guid>
      <dc:creator>ghannemann</dc:creator>
      <dc:date>2015-08-28T02:05:53Z</dc:date>
    </item>
  </channel>
</rss>

