<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to Receive Data from universal forwarder to splunk server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/554510#M91897</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have recently deployed Universal forwarder on Ubuntu and and the server on other Linux machine. I am unable to receive data from the forwarder at all. I am unable to fetch any data when I click Data Summery on the Splunk interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 16:44:47 GMT</pubDate>
    <dc:creator>AmyShah</dc:creator>
    <dc:date>2021-06-04T16:44:47Z</dc:date>
    <item>
      <title>Unable to Receive Data from universal forwarder to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/554510#M91897</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have recently deployed Universal forwarder on Ubuntu and and the server on other Linux machine. I am unable to receive data from the forwarder at all. I am unable to fetch any data when I click Data Summery on the Splunk interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 16:44:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/554510#M91897</guid>
      <dc:creator>AmyShah</dc:creator>
      <dc:date>2021-06-04T16:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Receive Data from universal forwarder to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/554524#M91900</link>
      <description>&lt;P&gt;Did you enable receiving on the Linux machine's port 9997?&lt;/P&gt;&lt;P&gt;Did you configure the UF to send data to the Linux machine?&amp;nbsp; Did you configure any inputs on the UF?&amp;nbsp; Have you checked the UF's splunkd.log?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 17:56:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/554524#M91900</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-06-04T17:56:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Receive Data from universal forwarder to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/554537#M91901</link>
      <description>Check also splunk server firewall and selinux configuration.</description>
      <pubDate>Fri, 04 Jun 2021 19:53:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/554537#M91901</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-06-04T19:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Receive Data from universal forwarder to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/564368#M100495</link>
      <description>&lt;P&gt;Check your logs on the SUF and the receiver/indexer. Easiest place to start. Is the SUF connecting and forwarding in the log? Are you receiving and indexing in the log?&lt;/P&gt;&lt;P&gt;From the SUF to receiver in `var/log/splunk/splunkd.log`:&lt;/P&gt;&lt;LI-CODE lang="c"&gt;08-23-2021 15:02:18.711 +0000 INFO  AutoLoadBalancedConnectionStrategy [1037 TcpOutEloop] - Found currently active indexer. Connected to idx=10.10.50.206:9997, reuse=1.&lt;/LI-CODE&gt;&lt;P&gt;On the receiver in `var/log/splunk/metrics.log`:&lt;/P&gt;&lt;LI-CODE lang="c"&gt;08-23-2021 15:04:16.198 +0000 INFO  Metrics - group=tcpin_connections, 10.10.50.209:37444:9997, connectionType=cooked, sourcePort=37444, sourceHost=10.10.50.209, sourceIp=10.10.50.209, destPort=9997, kb=15.651, _tcp_Bps=517.002, _tcp_KBps=0.505, _tcp_avg_thruput=12.605, _tcp_Kprocessed=41409.860, _tcp_eps=0.323, _process_time_ms=0, evt_misc_kBps=0.000, evt_raw_kBps=0.452, evt_fields_kBps=0.032, evt_fn_kBps=0.000, evt_fv_kBps=0.000, evt_fn_str_kBps=0.000, evt_fn_meta_dyn_kBps=0.000, evt_fn_meta_predef_kBps=0.000, evt_fn_meta_str_kBps=0.000, evt_fv_num_kBps=0.000, evt_fv_str_kBps=0.000, evt_fv_predef_kBps=0.000, evt_fv_offlen_kBps=0.000, evt_fv_fp_kBps=0.000, build=ddff1c41e5cf, version=8.2.1, os=Linux, arch=x86_64, hostname=spl-suf-01.ephemeric.lan, guid=752B1D7C-B3C5-43D3-A779-EB6C0FCAA965, fwdType=uf, ssl=false, lastIndexer=10.10.50.206:9997, ack=false&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;On the SUF:&lt;/P&gt;&lt;LI-CODE lang="c"&gt;ncat -v spl-idx-01.ephemeric.lan 9997
Ncat: Version 7.50 ( https://nmap.org/ncat )
Ncat: Connected to 10.10.50.206:9997.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Metrics on the SUF:&lt;/P&gt;&lt;LI-CODE lang="c"&gt;08-23-2021 15:12:21.012 +0000 INFO  Metrics - group=tcpout_connections, name=default-autolb-group:10.10.50.206:9997:0, sourcePort=8089, destIp=10.10.50.206, destPort=9997, _tcp_Bps=526.97, _tcp_KBps=0.51, _tcp_avg_thruput=11.06, _tcp_Kprocessed=41656, _tcp_eps=0.33, kb=15.44&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 15:12:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/564368#M100495</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2021-08-23T15:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Receive Data from universal forwarder to splunk server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/681575#M113882</link>
      <description>&lt;P&gt;did you ever get resolution on this?&lt;/P&gt;&lt;P&gt;My deployment server stopped servicing clients -- start throwing this error. No firewall or selinux issues as suggested below...&lt;/P&gt;</description>
      <pubDate>Thu, 21 Mar 2024 16:01:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-Receive-Data-from-universal-forwarder-to-splunk-server/m-p/681575#M113882</guid>
      <dc:creator>mykol_j</dc:creator>
      <dc:date>2024-03-21T16:01:04Z</dc:date>
    </item>
  </channel>
</rss>

