<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk list forward-server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/splunk-list-forward-server/m-p/46040#M8664</link>
    <description>&lt;P&gt;Excellent - when entering default credentials&lt;/P&gt;

&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\bin&amp;gt;splunk list forward-server&lt;/P&gt;

&lt;P&gt;Splunk username: admin / Password:&lt;/P&gt;

&lt;P&gt;Active forwards:        None&lt;/P&gt;

&lt;P&gt;Configured but inactive forwards:        splunk.xxx.com:9997&lt;/P&gt;

&lt;P&gt;Nothing further was done but some head scratching and coffee drinking, checked again and voila!&lt;/P&gt;

&lt;P&gt;Active forwards:        splunk.xxx.com:9997&lt;/P&gt;

&lt;P&gt;Configured but inactive forwards:        None&lt;/P&gt;

&lt;P&gt;Now to see if this can be replicated smoothly on my third server!&lt;/P&gt;</description>
    <pubDate>Thu, 28 Feb 2013 09:52:01 GMT</pubDate>
    <dc:creator>duncanuno</dc:creator>
    <dc:date>2013-02-28T09:52:01Z</dc:date>
    <item>
      <title>splunk list forward-server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-list-forward-server/m-p/46038#M8662</link>
      <description>&lt;P&gt;Hi, Windows query&lt;/P&gt;

&lt;P&gt;I have a non AD Windows server 2008R2 setup x 3 servers. Simple setup for 2 servers to send data to Splunk server on 3rd server.&lt;BR /&gt;
"Splunk" server with latest version of Splunk installed using Splunk web userid "admin", receiver port setup for default 9997&lt;/P&gt;

&lt;P&gt;Second server where I have run splunkforwarder5.02....msi and at no stage am I prompted for user id or password. Selected all options however no certificate info. When testing to see status of forwarder (after restarting both Splunk and forwarder server) I get asked for a userid: and password:. Is this the Splunk web userid? - have tried this and fails, also tried the local admin userid - fails.&lt;/P&gt;

&lt;P&gt;Firewalls on both disabled - am getting prompted for userid however I am not sure where this challenge is being generated.&lt;/P&gt;

&lt;P&gt;Any ideas please?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 17:09:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-list-forward-server/m-p/46038#M8662</guid>
      <dc:creator>duncanuno</dc:creator>
      <dc:date>2013-02-27T17:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: splunk list forward-server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-list-forward-server/m-p/46039#M8663</link>
      <description>&lt;P&gt;Splunk is asking you to login as you're performing an action that requires you to be authenticated. The passwords on one instance are completely independent one another, and the default credentials will always be an l/p of admin/changeme.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 21:53:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-list-forward-server/m-p/46039#M8663</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2013-02-27T21:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: splunk list forward-server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/splunk-list-forward-server/m-p/46040#M8664</link>
      <description>&lt;P&gt;Excellent - when entering default credentials&lt;/P&gt;

&lt;P&gt;C:\Program Files\SplunkUniversalForwarder\bin&amp;gt;splunk list forward-server&lt;/P&gt;

&lt;P&gt;Splunk username: admin / Password:&lt;/P&gt;

&lt;P&gt;Active forwards:        None&lt;/P&gt;

&lt;P&gt;Configured but inactive forwards:        splunk.xxx.com:9997&lt;/P&gt;

&lt;P&gt;Nothing further was done but some head scratching and coffee drinking, checked again and voila!&lt;/P&gt;

&lt;P&gt;Active forwards:        splunk.xxx.com:9997&lt;/P&gt;

&lt;P&gt;Configured but inactive forwards:        None&lt;/P&gt;

&lt;P&gt;Now to see if this can be replicated smoothly on my third server!&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2013 09:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/splunk-list-forward-server/m-p/46040#M8664</guid>
      <dc:creator>duncanuno</dc:creator>
      <dc:date>2013-02-28T09:52:01Z</dc:date>
    </item>
  </channel>
</rss>

