<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Enterprise doesn't detect universal forwarder (linux) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-doesn-t-detect-universal-forwarder-linux/m-p/535818#M89852</link>
    <description>&lt;P&gt;I have one machine with Splunk Enterprise and on another machines I've installed a universal forwarder. Even-though everything seems ok from the installation point of view, somehow&amp;nbsp; Spunk Enterprise does not detect the forwarder:&lt;/P&gt;&lt;P&gt;- In the Splunk Web interface I've&amp;nbsp; enabled receiving on port 9997 (&lt;SPAN&gt; Splunk Web: Settings -&amp;gt; Forwarding and receiving )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- After installing the forwarder (linux) , I've started it from /bin :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./splunk start (accepted&amp;nbsp;license)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./splunk add forward-server &amp;lt;splunk_web_server&amp;gt;:9997&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;# add a source&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./splunk add monitor /var/log/auth.log -sourcetype linux_secure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./splunk restart&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am I missing something ? Thx&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2021 11:22:09 GMT</pubDate>
    <dc:creator>dejanu</dc:creator>
    <dc:date>2021-01-14T11:22:09Z</dc:date>
    <item>
      <title>Splunk Enterprise doesn't detect universal forwarder (linux)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-doesn-t-detect-universal-forwarder-linux/m-p/535818#M89852</link>
      <description>&lt;P&gt;I have one machine with Splunk Enterprise and on another machines I've installed a universal forwarder. Even-though everything seems ok from the installation point of view, somehow&amp;nbsp; Spunk Enterprise does not detect the forwarder:&lt;/P&gt;&lt;P&gt;- In the Splunk Web interface I've&amp;nbsp; enabled receiving on port 9997 (&lt;SPAN&gt; Splunk Web: Settings -&amp;gt; Forwarding and receiving )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- After installing the forwarder (linux) , I've started it from /bin :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./splunk start (accepted&amp;nbsp;license)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./splunk add forward-server &amp;lt;splunk_web_server&amp;gt;:9997&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;# add a source&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./splunk add monitor /var/log/auth.log -sourcetype linux_secure&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;./splunk restart&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Am I missing something ? Thx&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 11:22:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-doesn-t-detect-universal-forwarder-linux/m-p/535818#M89852</guid>
      <dc:creator>dejanu</dc:creator>
      <dc:date>2021-01-14T11:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise doesn't detect universal forwarder (linux)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-doesn-t-detect-universal-forwarder-linux/m-p/535826#M89853</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230489"&gt;@dejanu&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Possible options are;&lt;/P&gt;&lt;P&gt;1- On Splunk Enterprise machine, firewall may be blocking 9997 port access. Please check firewall.&lt;/P&gt;&lt;P&gt;2- Check internal logs for client host with;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=forwarder_hostname&lt;/LI-CODE&gt;&lt;P&gt;3- If below steps are ok maybe there is permission problem. If you start UF on linux with splunk user, by default splunk user cannot read "&lt;SPAN&gt;/var/log/auth.log" file. You should give read permission to splunk user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If this reply helps you an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 12:02:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Enterprise-doesn-t-detect-universal-forwarder-linux/m-p/535826#M89853</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-01-14T12:02:24Z</dc:date>
    </item>
  </channel>
</rss>

