<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder is working but data is not shown in splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-working-but-data-is-not-shown-in-splunk/m-p/339505#M92717</link>
    <description>&lt;P&gt;There are a ton of reasons.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Is splunk running?
Is inputs.conf configured to send anything?
Is outputs.conf configured to show where to send it?
Does the forwarder have a route to the indexer hosts?
Do the firewalls and  other network equipment allow connections from the UF to the indexers (port 9997 or maybe 9998 or ???)?
Is _time correct for your events (maybe being thrown into the future)?
Are you indexers setup to receive anything?
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 02 Aug 2017 03:16:36 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2017-08-02T03:16:36Z</dc:date>
    <item>
      <title>Forwarder is working but data is not shown in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-working-but-data-is-not-shown-in-splunk/m-p/339503#M92715</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We have a setup in a remote machine that receives data from database in form of excel sheets and forwards it to Splunk environment &lt;BR /&gt;
with the help of a universal forwarder.&lt;BR /&gt;
But when i am searching that particular data it is not coming in splunk. Any idea why this is happening even if the .conf files are fine?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 04:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-working-but-data-is-not-shown-in-splunk/m-p/339503#M92715</guid>
      <dc:creator>ASISH_9</dc:creator>
      <dc:date>2017-08-01T04:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder is working but data is not shown in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-working-but-data-is-not-shown-in-splunk/m-p/339504#M92716</link>
      <description>&lt;P&gt;Are you monitoring file on UF? Following are good source to debug&lt;/P&gt;

&lt;P&gt;&lt;A href="https://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs"&gt;https://wiki.splunk.com/Community:Troubleshooting_Monitor_Inputs&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/177588/how-to-debug-why-a-universal-forwarder-is-reading.html"&gt;https://answers.splunk.com/answers/177588/how-to-debug-why-a-universal-forwarder-is-reading.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 08:50:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-working-but-data-is-not-shown-in-splunk/m-p/339504#M92716</guid>
      <dc:creator>hardikJsheth</dc:creator>
      <dc:date>2017-08-01T08:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder is working but data is not shown in splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-working-but-data-is-not-shown-in-splunk/m-p/339505#M92717</link>
      <description>&lt;P&gt;There are a ton of reasons.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Is splunk running?
Is inputs.conf configured to send anything?
Is outputs.conf configured to show where to send it?
Does the forwarder have a route to the indexer hosts?
Do the firewalls and  other network equipment allow connections from the UF to the indexers (port 9997 or maybe 9998 or ???)?
Is _time correct for your events (maybe being thrown into the future)?
Are you indexers setup to receive anything?
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 02 Aug 2017 03:16:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-is-working-but-data-is-not-shown-in-splunk/m-p/339505#M92717</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-08-02T03:16:36Z</dc:date>
    </item>
  </channel>
</rss>

