<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk forwarder issue after installation in Windows in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496649#M84712</link>
    <description>&lt;P&gt;Hi brainsarmiento,&lt;/P&gt;

&lt;P&gt;assuming you ran the &lt;CODE&gt;netstat&lt;/CODE&gt; on the nix indexer to check port &lt;CODE&gt;9991&lt;/CODE&gt; - that might sound like a networking/routing/firewall issue.&lt;BR /&gt;
Here is also a good troubleshooting guide &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata&lt;/A&gt; if it's not related to connectivity.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jan 2020 21:31:50 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2020-01-27T21:31:50Z</dc:date>
    <item>
      <title>Splunk forwarder issue after installation in Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496648#M84711</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;

&lt;P&gt;I'm having several issues after installing Splunk Forwarder on Any Win10 Device. (Win 10, Win Server 2012,2016).&lt;/P&gt;

&lt;P&gt;I'm using the following line:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;msiexec.exe /i splunkforwarder-7.3.4.msi FORWARD_SERVER="ADDserver:9991" WINEVENTLOG_SEC_ENABLE=0 WINEVENTLOG_SYS_ENABLE=0 SPLUNKPASSWORD=*Password* /L*v logfile.txt LAUNCHSPLUNK=1 SERVICESTARTTYPE=auto AGREETOLICENSE=yes /quiet
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The App gets installed and but no Logs packages are sent to the Server, The netstat command doesn't show me any: 9991 port connection. &lt;BR /&gt;
I've done the confirmation using "sc query SplunkForwarder" and the service is running, but again no log gets to be sent to my Splunk Console (Server).&lt;/P&gt;

&lt;P&gt;Help please, I'll provide any information you want to know. Or that I'm missing&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 20:58:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496648#M84711</guid>
      <dc:creator>briansarmiento</dc:creator>
      <dc:date>2020-01-27T20:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder issue after installation in Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496649#M84712</link>
      <description>&lt;P&gt;Hi brainsarmiento,&lt;/P&gt;

&lt;P&gt;assuming you ran the &lt;CODE&gt;netstat&lt;/CODE&gt; on the nix indexer to check port &lt;CODE&gt;9991&lt;/CODE&gt; - that might sound like a networking/routing/firewall issue.&lt;BR /&gt;
Here is also a good troubleshooting guide &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Cantfinddata&lt;/A&gt; if it's not related to connectivity.&lt;/P&gt;

&lt;P&gt;Hope this helps ...&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 21:31:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496649#M84712</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2020-01-27T21:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder issue after installation in Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496650#M84713</link>
      <description>&lt;P&gt;Hi MuS,&lt;/P&gt;

&lt;P&gt;how can I confirm its a Firewall issue?, Cause all of my infrastructure its connected to LAN.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 22:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496650#M84713</guid>
      <dc:creator>briansarmiento</dc:creator>
      <dc:date>2020-01-27T22:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder issue after installation in Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496651#M84714</link>
      <description>&lt;P&gt;Login to one server that runs the universal forwarder and run a &lt;CODE&gt;telnet ADDserver 9991&lt;/CODE&gt; and see if you get a connection established or a timeout.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 00:05:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496651#M84714</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2020-01-28T00:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk forwarder issue after installation in Windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496652#M84715</link>
      <description>&lt;P&gt;Hi @briansarmiento,&lt;/P&gt;

&lt;P&gt;The property to set to specify an indexer for the UF is &lt;CODE&gt;RECEIVING_INDEXER&lt;/CODE&gt;, not &lt;CODE&gt;FORWARD_SERVER&lt;/CODE&gt;.  Please see here: &lt;A href="https://docs.splunk.com/Documentation/Forwarder/7.3.4/Forwarder/InstallaWindowsuniversalforwarderfromthecommandline"&gt;https://docs.splunk.com/Documentation/Forwarder/7.3.4/Forwarder/InstallaWindowsuniversalforwarderfromthecommandline&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Cheers,&lt;/P&gt;

&lt;P&gt;- Jo.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 10:49:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-forwarder-issue-after-installation-in-Windows/m-p/496652#M84715</guid>
      <dc:creator>jhornsby_splunk</dc:creator>
      <dc:date>2020-01-28T10:49:47Z</dc:date>
    </item>
  </channel>
</rss>

