<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New Splunk Installation Not Recieving Logs in Installation</title>
    <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43346#M9259</link>
    <description>&lt;P&gt;The log file reports:&lt;/P&gt;

&lt;P&gt;No connection could be made because the target machine actively refused it.&lt;/P&gt;

&lt;P&gt;That is looking on port 9997 (the default).  When I try to add that port to Splunk's TCP data inputs, I get a "Parameter name: TCP port 9997 is not available".  That port is not setup as a UDP port either.&lt;/P&gt;

&lt;P&gt;This splunk host isn't recieving any data from any forwader.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jan 2012 15:57:39 GMT</pubDate>
    <dc:creator>nmace</dc:creator>
    <dc:date>2012-01-04T15:57:39Z</dc:date>
    <item>
      <title>New Splunk Installation Not Recieving Logs</title>
      <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43342#M9255</link>
      <description>&lt;P&gt;I've got a new install of Splunk that refuses to receive logs from any of Windows servers.  I have the Splunk Universal Forwarder installed on the machine I want to gather logs from.  I left the port setting on the default.  However the only logs the Splunk server seems to be receiving is local log files.  I'm not sure what the problem is, I didn't have this problem when I setup Splunk before previously.  Maybe I'm overlooking something obvious?  I'm using the current release of Splunk as well as the current release of the forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2012 20:01:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43342#M9255</guid>
      <dc:creator>nmace</dc:creator>
      <dc:date>2012-01-03T20:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: New Splunk Installation Not Recieving Logs</title>
      <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43343#M9256</link>
      <description>&lt;P&gt;Any firewall between forwarder and splunk server?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2012 20:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43343#M9256</guid>
      <dc:creator>Spelunke</dc:creator>
      <dc:date>2012-01-03T20:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: New Splunk Installation Not Recieving Logs</title>
      <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43344#M9257</link>
      <description>&lt;P&gt;Nope.  No hardware firewall, no software firewall either.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2012 20:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43344#M9257</guid>
      <dc:creator>nmace</dc:creator>
      <dc:date>2012-01-03T20:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: New Splunk Installation Not Recieving Logs</title>
      <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43345#M9258</link>
      <description>&lt;P&gt;here are some steps :&lt;BR /&gt;
 - check $SPLUNK_HOME/var/log/splunk/splunkd.log on the forwarder to see if it complains about : network issue, or log collection.&lt;BR /&gt;
 - maybe the internal logs are forwarded but not the windows events (check index=_internal | stats count by host )&lt;BR /&gt;
 - is the indexer receiving data from other forwarders ?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:16:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43345#M9258</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-28T10:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: New Splunk Installation Not Recieving Logs</title>
      <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43346#M9259</link>
      <description>&lt;P&gt;The log file reports:&lt;/P&gt;

&lt;P&gt;No connection could be made because the target machine actively refused it.&lt;/P&gt;

&lt;P&gt;That is looking on port 9997 (the default).  When I try to add that port to Splunk's TCP data inputs, I get a "Parameter name: TCP port 9997 is not available".  That port is not setup as a UDP port either.&lt;/P&gt;

&lt;P&gt;This splunk host isn't recieving any data from any forwader.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2012 15:57:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43346#M9259</guid>
      <dc:creator>nmace</dc:creator>
      <dc:date>2012-01-04T15:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: New Splunk Installation Not Recieving Logs</title>
      <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43347#M9260</link>
      <description>&lt;P&gt;The log file reports:&lt;/P&gt;

&lt;P&gt;No connection could be made because the target machine actively refused it.&lt;/P&gt;

&lt;P&gt;That is looking on port 9997 (the default).  When I try to add that port to Splunk's TCP data inputs, I get a "Parameter name: TCP port 9997 is not available".  That port is not setup as a UDP port either.&lt;/P&gt;

&lt;P&gt;This splunk host isn't recieving any data from any forwader.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2012 15:57:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43347#M9260</guid>
      <dc:creator>nmace</dc:creator>
      <dc:date>2012-01-04T15:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: New Splunk Installation Not Recieving Logs</title>
      <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43348#M9261</link>
      <description>&lt;P&gt;Use netstats to see which process is using your port 9997 TCP.&lt;/P&gt;

&lt;P&gt;udp, tcp and splunktcp are different protocols, you want splunktcp. &lt;BR /&gt;
To configure splunk to receive forwarded data, please go to &lt;BR /&gt;
manager &amp;gt; forwarding &amp;amp; receiving &amp;gt; receiving &amp;gt; add the port 9997.&lt;BR /&gt;
(and disable the inputs you may have created in inputs)&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2012 18:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43348#M9261</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-01-04T18:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: New Splunk Installation Not Recieving Logs</title>
      <link>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43349#M9262</link>
      <description>&lt;P&gt;That fixed it, thanks!  Netstat revealed something else was using port 9997.  Fixing that, then deleting my inputs and setting it up under "Recieving" fixed the problem.  Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jan 2012 20:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/New-Splunk-Installation-Not-Recieving-Logs/m-p/43349#M9262</guid>
      <dc:creator>nmace</dc:creator>
      <dc:date>2012-01-04T20:24:30Z</dc:date>
    </item>
  </channel>
</rss>

