<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows universal forwarder to Splunk Cloud issues in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549083#M91245</link>
    <description>&lt;P&gt;I am trialing the Splunk Cloud software and having read through all the information on how to setup universal forwarders i've reached an impasse.&lt;/P&gt;&lt;P&gt;I believe i have setup the forwarder correctly: -&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;installed forwader&lt;/LI&gt;&lt;LI&gt;incoprorated .spl certificate&lt;/LI&gt;&lt;LI&gt;added logs to monitor&lt;/LI&gt;&lt;LI&gt;added the forward-server details&lt;/LI&gt;&lt;LI&gt;restarted splunk.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I have opened ports 8089 and 9997 inbound/outbound to ensure not firewall blocking traffic.&lt;/P&gt;&lt;P&gt;The documentation then seems to indicate that in the Splunk Cloud UI should see under under Settings --&amp;gt; Forwarding &amp;amp; Receiving option or a Forwarder under Data Inputs.&lt;/P&gt;&lt;P&gt;I don't see either and as such can setup a data source.&lt;/P&gt;&lt;P&gt;Could anyone advise if i have missed a step somewhere on client side universal forwarder setup or whether it is something within Splunk Cloud i have failed to do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Apr 2021 08:33:26 GMT</pubDate>
    <dc:creator>AndyC1</dc:creator>
    <dc:date>2021-04-23T08:33:26Z</dc:date>
    <item>
      <title>Windows universal forwarder to Splunk Cloud issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549083#M91245</link>
      <description>&lt;P&gt;I am trialing the Splunk Cloud software and having read through all the information on how to setup universal forwarders i've reached an impasse.&lt;/P&gt;&lt;P&gt;I believe i have setup the forwarder correctly: -&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;installed forwader&lt;/LI&gt;&lt;LI&gt;incoprorated .spl certificate&lt;/LI&gt;&lt;LI&gt;added logs to monitor&lt;/LI&gt;&lt;LI&gt;added the forward-server details&lt;/LI&gt;&lt;LI&gt;restarted splunk.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I have opened ports 8089 and 9997 inbound/outbound to ensure not firewall blocking traffic.&lt;/P&gt;&lt;P&gt;The documentation then seems to indicate that in the Splunk Cloud UI should see under under Settings --&amp;gt; Forwarding &amp;amp; Receiving option or a Forwarder under Data Inputs.&lt;/P&gt;&lt;P&gt;I don't see either and as such can setup a data source.&lt;/P&gt;&lt;P&gt;Could anyone advise if i have missed a step somewhere on client side universal forwarder setup or whether it is something within Splunk Cloud i have failed to do?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 08:33:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549083#M91245</guid>
      <dc:creator>AndyC1</dc:creator>
      <dc:date>2021-04-23T08:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: Windows universal forwarder to Splunk Cloud issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549108#M91246</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233763"&gt;@AndyC1&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;is it a windows or linux forwarder? have you defined the inputs.conf on your forwarder?&lt;/P&gt;&lt;P&gt;if yes, can you share the inputs.conf and outputs.conf stanza?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 12:04:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549108#M91246</guid>
      <dc:creator>aasabatini</dc:creator>
      <dc:date>2021-04-23T12:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: Windows universal forwarder to Splunk Cloud issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549114#M91247</link>
      <description>&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/233763"&gt;@AndyC1&lt;/a&gt; , I found the setup of forwarders to the cloud tricky. However, when I followed the step-by-step process in &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2103/Admin/WindowsGDI" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2103/Admin/WindowsGDI&lt;/A&gt; it worked for me.</description>
      <pubDate>Fri, 23 Apr 2021 12:15:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549114#M91247</guid>
      <dc:creator>edgarrity</dc:creator>
      <dc:date>2021-04-23T12:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: Windows universal forwarder to Splunk Cloud issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549116#M91248</link>
      <description>&lt;P&gt;hi there,&lt;/P&gt;&lt;P&gt;according to the docs&lt;/P&gt;&lt;P&gt;When you work with forwarders to send data to Splunk Cloud, you must download an app that has the credentials specific to your Splunk Cloud instance. You install the forwarder credentials app on your universal forwarder, heavy forwarder, or deployment server, and it lets you connect to Splunk Cloud.&lt;/P&gt;&lt;P&gt;If everything is correct try following steps:&lt;/P&gt;&lt;P&gt;try doing telnet to the cloud instance from your splunk forwarder&lt;/P&gt;&lt;P&gt;telnet &amp;lt;IP&amp;gt; &amp;lt;port&amp;gt;&lt;/P&gt;&lt;P&gt;telnet 192.168.1.1 9997&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and/or on your forwarder server run following commands&lt;/P&gt;&lt;P&gt;/splunkforwarder/bin/splunk list forward-server&amp;nbsp; &amp;nbsp;( if all settings okay, it should come under&amp;nbsp;Active forwards else Configured but inactive forwards)&lt;/P&gt;&lt;P&gt;/splunkforwarder/bin/splunk show deploy-poll&amp;nbsp; &amp;nbsp; ( will show the deployment server configured)&lt;/P&gt;&lt;P&gt;/splunkforwarder/bin/splunk list monitor&amp;nbsp; (will list the files that splunk is watching)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also try doing tail or scan the end lines of splunkforwarder splunkd logs&lt;/P&gt;&lt;P&gt;/splunkforwarder/var/log/splunk/splunkd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ps: in windows you can use cmd to run splunk CLI commands, instead / use \ for paths.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 12:33:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549116#M91248</guid>
      <dc:creator>ayush1906</dc:creator>
      <dc:date>2021-04-23T12:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Windows universal forwarder to Splunk Cloud issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549150#M91253</link>
      <description>&lt;P&gt;Ayush,&lt;/P&gt;&lt;P&gt;Thank you for these suggestions.&lt;/P&gt;&lt;P&gt;Regards the deployment server it suggests you can set up a universal forwarder on a windows server to forward direct to Splunk Cloud that shouldn't need an enterprise Splunk to act as a deployment server is this correct? Or does the Cloud version become the deployment server in this scenario?&lt;/P&gt;&lt;P&gt;Checked the logs and actually ma seeing loads of below errors appearing.&lt;/P&gt;&lt;P&gt;04-23-2021 16:46:07.058 +0100 INFO DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;/P&gt;&lt;P&gt;Will try and test telnet connectivity next week as will need to open up ports and install.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;splunk list forward-server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Active forwards: inputs.prd-p-vk6k0.splunkcloud.com:9997 (ssl) Configured but inactive forwards: prd-p-vk6k0.splunkcloud.com:9997&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;splunk show deploy-poll&lt;/STRONG&gt;&lt;BR /&gt;Deployment Server URI is set to "prd-p-vk6k0.splunkcloud.com:8089".&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;splunk list monitor&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Monitored Directories:&lt;BR /&gt;$SPLUNK_HOME\var\log\splunk&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\audit.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\btool.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\conf.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\dfm_stderr.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\dfm_stdout.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\first_install.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\health.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\license_usage.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\metrics.log.1&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\mongod.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\remote_searches.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\scheduler.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\search_messages.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\searchhistory.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd-utility.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd_access.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd_ui_access.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\wlm_monitor.log&lt;BR /&gt;$SPLUNK_HOME\var\log\splunk\license_usage_summary.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\license_usage_summary.log&lt;BR /&gt;$SPLUNK_HOME\var\log\splunk\metrics.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\metrics.log&lt;BR /&gt;$SPLUNK_HOME\var\log\splunk\splunk_instrumentation_cloud.log*&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunk_instrumentation_cloud.log&lt;BR /&gt;$SPLUNK_HOME\var\log\splunk\splunkd.log&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log&lt;BR /&gt;$SPLUNK_HOME\var\log\watchdog\watchdog.log*&lt;BR /&gt;C:\Program Files\SplunkUniversalForwarder\var\log\watchdog\watchdog.log&lt;BR /&gt;$SPLUNK_HOME\var\run\splunk\search_telemetry\*search_telemetry.json&lt;BR /&gt;$SPLUNK_HOME\var\spool\splunk\...stash_new&lt;BR /&gt;Monitored Files:&lt;BR /&gt;$SPLUNK_HOME\etc\splunk.version&lt;BR /&gt;&lt;EM&gt;D:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\PELMAX761DEVSVR\SystemErr.log&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;D:\IBM\WebSphere\AppServer\profiles\AppSrv01\logs\PELMAX761DEVSVR\SystemOut.log&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;D:\IBM\WebSphere\AppServer\profiles\Dmgr01\logs\dmgr\SystemErr.log&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;D:\IBM\WebSphere\AppServer\profiles\Dmgr01\logs\dmgr\SystemOut.log&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 16:36:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549150#M91253</guid>
      <dc:creator>AndyC1</dc:creator>
      <dc:date>2021-04-23T16:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Windows universal forwarder to Splunk Cloud issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549151#M91254</link>
      <description>&lt;P&gt;Hi Ed,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes this is the same document i'm working off I think i must be inadvertently missign a step or missing one one thinking it's not needed, didn't do anythign with Deployment Server pre-req as thought the Cloud version didn't need when universal forwarder setup directly on a windows server manually?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 16:38:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549151#M91254</guid>
      <dc:creator>AndyC1</dc:creator>
      <dc:date>2021-04-23T16:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows universal forwarder to Splunk Cloud issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549153#M91255</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi assabatini,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;It is a windows server, I will have to check path locations for the .conf file and will post once have them though won't be until Monday now&lt;/P&gt;</description>
      <pubDate>Fri, 23 Apr 2021 16:41:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549153#M91255</guid>
      <dc:creator>AndyC1</dc:creator>
      <dc:date>2021-04-23T16:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Windows universal forwarder to Splunk Cloud issues</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549155#M91256</link>
      <description>My first attempt through the step-by-step using a Deployment Server to configure a Heavy Forwarder to send data to the cloud failed. I wound up with a Heavy Forwarder that could not provide the Web UI. So on my second attempt I just installed the forwarder config directly on the Heavy Forwarder and that was successful.</description>
      <pubDate>Fri, 23 Apr 2021 16:48:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Windows-universal-forwarder-to-Splunk-Cloud-issues/m-p/549155#M91256</guid>
      <dc:creator>edgarrity</dc:creator>
      <dc:date>2021-04-23T16:48:40Z</dc:date>
    </item>
  </channel>
</rss>

