<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558809#M92439</link>
    <description>&lt;P&gt;In my inputs.conf&lt;/P&gt;&lt;P&gt;[monitor://C:\Users\Lenovo\Documents\............\*.csv]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = index_fptsinv&lt;BR /&gt;sourcetype = csv&lt;/P&gt;&lt;P&gt;My ip is&amp;nbsp;192.168.29.117&lt;/P&gt;&lt;P&gt;I have to send to server with ip&amp;nbsp;139.23.76.80&lt;/P&gt;&lt;P&gt;Can u also tell me which Ip i've to provide in Deployement server and which in Receiver index?&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jul 2021 08:23:28 GMT</pubDate>
    <dc:creator>akankshayadav</dc:creator>
    <dc:date>2021-07-09T08:23:28Z</dc:date>
    <item>
      <title>Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558670#M92414</link>
      <description>&lt;P&gt;I have to forward my data from my machine to serval using universal forwarder. What should be the content of inputs.conf?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 12:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558670#M92414</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-07-08T12:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558676#M92415</link>
      <description>&lt;P&gt;Hi&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;## This is for linux, windows is slightly different
[monitor:&amp;lt;absolute_file_path&amp;gt;]
sourcetype = &amp;lt;sourcetype_name&amp;gt;
index = &amp;lt;index_name&amp;gt;

#Example
[monitor:///var/log/httpd]
sourcetype = access_common
index = main&lt;/LI-CODE&gt;&lt;P&gt;You can find more examples here -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#inputs.conf.example" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf#inputs.conf.example&lt;/A&gt;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;An upvote would be appreciated and Accept solution if this reply helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 12:27:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558676#M92415</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-08T12:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558677#M92416</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp; Provided were&amp;nbsp; least minimum config, however there are additional settings to be added depends on use case. Have a look at the link provided and read of splunk docs for detailed understanding.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;An upvote would be appreciated and Accept solution if this reply helps!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 12:33:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558677#M92416</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-08T12:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558714#M92419</link>
      <description>&lt;P&gt;I am giving this config in inputs.conf but can't see my data forwarded to the server&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 15:25:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558714#M92419</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-07-08T15:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558795#M92435</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp;Can you share what have you configured where did you deploy it?&lt;/P&gt;&lt;P&gt;Do you know the index that you are using already created in Splunk?&lt;/P&gt;&lt;P&gt;The file you want to monitor having enough read permissions and having contents in it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 05:17:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558795#M92435</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-09T05:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558809#M92439</link>
      <description>&lt;P&gt;In my inputs.conf&lt;/P&gt;&lt;P&gt;[monitor://C:\Users\Lenovo\Documents\............\*.csv]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = index_fptsinv&lt;BR /&gt;sourcetype = csv&lt;/P&gt;&lt;P&gt;My ip is&amp;nbsp;192.168.29.117&lt;/P&gt;&lt;P&gt;I have to send to server with ip&amp;nbsp;139.23.76.80&lt;/P&gt;&lt;P&gt;Can u also tell me which Ip i've to provide in Deployement server and which in Receiver index?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 08:23:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558809#M92439</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-07-09T08:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558935#M92465</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp; Can you follow this thread -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Props-conf-settings-are-not-working/m-p/558806#M92437" target="_blank"&gt;Props.conf settings are not working - Splunk Community&lt;/A&gt;&amp;nbsp;which is similar to what you are trying to achieve. You need to set-up other .conf files like outputs.conf (must).. props.conf (optional) etc.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Hope this reply helps!&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jul 2021 10:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/558935#M92465</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-10T10:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/559007#M92473</link>
      <description>&lt;P&gt;NO. This isn't my requirement . In my case , data is not received.&lt;BR /&gt;However, can you help with this&lt;/P&gt;&lt;P&gt;My ip is&amp;nbsp;192.168.29.117&lt;/P&gt;&lt;P&gt;I have to send to server with ip&amp;nbsp;139.23.76.80&lt;/P&gt;&lt;P&gt;Can u also tell me which Ip i've to provide in Deployement server and which in Receiver index?&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 04:24:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/559007#M92473</guid>
      <dc:creator>akankshayadav</dc:creator>
      <dc:date>2021-07-12T04:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/559008#M92474</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234662"&gt;@akankshayadav&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are using forward management using Deployment server (DS) then '&lt;SPAN&gt;My ip is&amp;nbsp;192.168.29.117'&amp;nbsp; shall be added to serverclass.conf in DS (this step is optional if you have configured inputs.conf directly on UF).&amp;nbsp;139.23.76.80 should have been your intermediate forwarder/indexer IP shall be in outputs.conf on UF where you have configured inputs.conf.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When you complete the above set-up and could not find the logs, then there could be many other reasons for not ingesting data to Splunk, check the splunkd.log of UF or you can query same in _internal index.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;An upvote would be appreciated if this reply help you!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Jul 2021 04:36:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder/m-p/559008#M92474</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-12T04:36:34Z</dc:date>
    </item>
  </channel>
</rss>

