<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Not able to see my windows client logs on Splunk Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89844#M97313</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have splunk installed on CentOS and i want to monitor a log file which is located on a windows host D drive . &lt;/P&gt;

&lt;P&gt;I have configured the forwarder on my windows client were i added that log file in data input.&lt;/P&gt;

&lt;P&gt;can you please advise what i can do next so i can see those logs in my centOS based splunk server.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Chandan&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jul 2012 21:31:43 GMT</pubDate>
    <dc:creator>royalchandu</dc:creator>
    <dc:date>2012-07-03T21:31:43Z</dc:date>
    <item>
      <title>Not able to see my windows client logs on Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89844#M97313</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have splunk installed on CentOS and i want to monitor a log file which is located on a windows host D drive . &lt;/P&gt;

&lt;P&gt;I have configured the forwarder on my windows client were i added that log file in data input.&lt;/P&gt;

&lt;P&gt;can you please advise what i can do next so i can see those logs in my centOS based splunk server.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Chandan&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2012 21:31:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89844#M97313</guid>
      <dc:creator>royalchandu</dc:creator>
      <dc:date>2012-07-03T21:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to see my windows client logs on Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89845#M97314</link>
      <description>&lt;P&gt;Could you please paste your relevant inputs and outputs settings. Are you getting other events from the forwarder, just not these?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jul 2012 21:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89845#M97314</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-07-03T21:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to see my windows client logs on Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89846#M97315</link>
      <description>&lt;P&gt;Below is the ethereal output of my splunk server my windows host IP is 10.20.30.191 .&lt;/P&gt;

&lt;P&gt;tethereal -i any port 9997&lt;BR /&gt;
Running as user "root" and group "root". This could be dangerous.&lt;BR /&gt;
Capturing on Pseudo-device that captures on all interfaces&lt;BR /&gt;
  0.000000  172.16.10.4 -&amp;gt; 10.20.30.56  TCP 50761 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=2522376187 TSER=0 WS=2&lt;BR /&gt;
  3.019068 172.16.10.12 -&amp;gt; 10.20.30.56  TCP 44395 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=951490862 TSER=0 WS=2&lt;BR /&gt;
  3.019953 172.16.10.12 -&amp;gt; 10.20.30.56  TCP 44396 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=951490863 TSER=0 WS=2&lt;BR /&gt;
  3.020985 172.16.10.12 -&amp;gt; 10.20.30.56  TCP 44397 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=951490864 TSER=0 WS=2&lt;BR /&gt;
  5.839795  172.16.10.6 -&amp;gt; 10.20.30.56  TCP 51269 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=2464781189 TSER=0 WS=7&lt;BR /&gt;
  6.018377 172.16.10.12 -&amp;gt; 10.20.30.56  TCP 44395 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=951493862 TSER=0 WS=2&lt;BR /&gt;
  6.019417 172.16.10.12 -&amp;gt; 10.20.30.56  TCP 44396 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=951493863 TSER=0 WS=2&lt;BR /&gt;
  6.020440 172.16.10.12 -&amp;gt; 10.20.30.56  TCP 44397 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=951493864 TSER=0 WS=2&lt;BR /&gt;
  6.272273  172.16.10.8 -&amp;gt; 10.20.30.56  TCP 50072 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=401096443 TSER=0 WS=2&lt;BR /&gt;
  7.920443  172.16.10.5 -&amp;gt; 10.20.30.56  TCP 35892 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380&lt;BR /&gt;
  8.015665 172.16.10.12 -&amp;gt; 10.20.30.56  TCP 44400 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=951495859 TSER=0 WS=2&lt;BR /&gt;
  8.840211  172.16.10.6 -&amp;gt; 10.20.30.56  TCP 51269 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=2464784190 TSER=0 WS=7&lt;BR /&gt;
  9.230324 10.20.30.191 -&amp;gt; 10.20.30.56  TCP 49521 &amp;gt; palace-6 [FIN, ACK] Seq=1 Ac                 k=1 Win=256 Len=0&lt;BR /&gt;
  9.230425  10.20.30.56 -&amp;gt; 10.20.30.191 TCP palace-6 &amp;gt; 49521 [FIN, ACK] Seq=1 Ac                 k=2 Win=229 Len=0&lt;BR /&gt;
  9.230545 10.20.30.191 -&amp;gt; 10.20.30.56  SMPP SMPP Cancel_sm&lt;BR /&gt;
  9.230551  10.20.30.56 -&amp;gt; 10.20.30.191 TCP palace-6 &amp;gt; 58418 [ACK] Seq=1 Ack=432                  Win=1002 Len=0&lt;BR /&gt;
  9.230649 10.20.30.191 -&amp;gt; 10.20.30.56  TCP 49521 &amp;gt; palace-6 [ACK] Seq=2 Ack=2 W                 in=256 Len=0&lt;BR /&gt;
  9.230674 10.20.30.191 -&amp;gt; 10.20.30.56  TCP 49527 &amp;gt; palace-6 [SYN] Seq=0 Win=819                 2 Len=0 MSS=1460 WS=8&lt;BR /&gt;
  9.230702  10.20.30.56 -&amp;gt; 10.20.30.191 TCP palace-6 &amp;gt; 49527 [SYN, ACK] Seq=0 Ac                 k=1 Win=14600 Len=0 MSS=1460 WS=6&lt;BR /&gt;
  9.230872 10.20.30.191 -&amp;gt; 10.20.30.56  TCP 49527 &amp;gt; palace-6 [ACK] Seq=1 Ack=1 W                 in=65536 Len=0&lt;BR /&gt;
  9.271718  172.16.10.8 -&amp;gt; 10.20.30.56  TCP 50072 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=401099443 TSER=0 WS=2&lt;BR /&gt;
 10.920291  172.16.10.5 -&amp;gt; 10.20.30.56  TCP 35892 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380&lt;BR /&gt;
 11.016066 172.16.10.12 -&amp;gt; 10.20.30.56  TCP 44400 &amp;gt; palace-6 [SYN] Seq=0 Win=584                 0 Len=0 MSS=1380 TSV=951498859 TSER=0 WS=2&lt;BR /&gt;
 14.841321  172.16.10.6 -&amp;gt; 10.20.30.56  TCP 51269 &amp;gt; palace-6 [SYN] Seq=0 Win=5840 Le             n=0 MSS=1380 TSV=2464790190 TSER=0 WS=7&lt;BR /&gt;
 15.228675 172.16.10.11 -&amp;gt; 10.20.30.56  TCP 55797 &amp;gt; palace-6 [SYN] Seq=0 Win=5840 Le             n=0 MSS=1380 TSV=2524005403 TSER=0 WS=2&lt;BR /&gt;
 16.921152  172.16.10.5 -&amp;gt; 10.20.30.56  TCP 35892 &amp;gt; palace-6 [SYN] Seq=0 Win=5840 Le             n=0 MSS=1380&lt;BR /&gt;
 18.228286 172.16.10.11 -&amp;gt; 10.20.30.56  TCP 55797 &amp;gt; palace-6 [SYN] Seq=0 Win=5840 Len=0 MSS=1380 TSV=2524008403 TSER=0 WS=2&lt;BR /&gt;
 21.000422  172.16.10.4 -&amp;gt; 10.20.30.56  TCP 50775 &amp;gt; palace-6 [SYN] Seq=0 Win=5840 Len=0 MSS=1380 TSV=2522397186 TSER=0 WS=2&lt;BR /&gt;
 24.000003  172.16.10.4 -&amp;gt; 10.20.30.56  TCP 50775 &amp;gt; palace-6 [SYN] Seq=0 Win=5840 Len=0 MSS=1380 TSV=2522400186 TSER=0 WS=2&lt;BR /&gt;
 24.228172 172.16.10.11 -&amp;gt; 10.20.30.56  TCP 55797 &amp;gt; palace-6 [SYN] Seq=0 Win=5840 Len=0 MSS=1380 TSV=2524014403 TSER=0 WS=2&lt;BR /&gt;
^C30 packets captured.&lt;/P&gt;

&lt;P&gt;Yes i am getting other events on my splunk server.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jul 2012 06:16:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89846#M97315</guid>
      <dc:creator>royalchandu</dc:creator>
      <dc:date>2012-07-04T06:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to see my windows client logs on Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89847#M97316</link>
      <description>&lt;P&gt;I'm having a similar problem. Splunk server is installed and receives logs via syslog-ng server on the same host and also some logs from splunk forwarder installed on unix systems. I've installed the universal forwarder on a couple of windows hosts and can't get messages to show up. I can see the connection is active both on client and server (netstat). I can also see that &lt;EM&gt;something&lt;/EM&gt; is gettight through, but it's unreadable:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;--splunk-cooked-mode-v3-- \x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00xspv201vc\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x008089\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00@\x00\x00\x00\x1\x00\x00\x00\x13__s2s_capabilities\x00\x00\x00\x00\x14ack=0;compression=0\x00\x00\x00\x00\x00\x00\x00\x00\x5_raw\x00
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This worked well in a test environment I set up, no idea why it doesn't here. There seems to be connectivity, so I'm currently working from the assumption there's something wonky with format of the data. &lt;/P&gt;

&lt;P&gt;I will admit I'm a bit in over my head here (pretty new to splunk) and any pointers from Splunk Ninjas would be appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 12:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-able-to-see-my-windows-client-logs-on-Splunk-Server/m-p/89847#M97316</guid>
      <dc:creator>steinb</dc:creator>
      <dc:date>2012-07-27T12:57:01Z</dc:date>
    </item>
  </channel>
</rss>

