<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Client not reporting in Splunk in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431996#M6382</link>
    <description>&lt;P&gt;Another observation is:&lt;/P&gt;

&lt;P&gt;The folder &lt;STRONG&gt;100_&lt;EM&gt;CompanyName&lt;/EM&gt;_splunkcloud&lt;/STRONG&gt; is not getting created when installing splunk in the path &lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\&lt;/CODE&gt;.  I am able to see that folder in the reporting servers. And in that folder &lt;CODE&gt;Pem&lt;/CODE&gt; file, &lt;CODE&gt;ouputs.conf&lt;/CODE&gt; etc. exists.&lt;/P&gt;

&lt;P&gt;This causing the issue?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 22:58:57 GMT</pubDate>
    <dc:creator>sugandhakumar</dc:creator>
    <dc:date>2020-09-29T22:58:57Z</dc:date>
    <item>
      <title>Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431992#M6378</link>
      <description>&lt;P&gt;Two of my servers not reporting in Splunk. They are running in windows server 2012 r2 std and 2016 datacenter. Splunk universal forwarder 7.2.0 installed in both servers.&lt;/P&gt;

&lt;P&gt;Please find find my below observations:&lt;/P&gt;

&lt;P&gt;1.Iam able to telnet the below IPs. &lt;BR /&gt;
telnet 54.157.x.x 9997 &lt;BR /&gt;
telnet 34.197.x.x 9997 &lt;BR /&gt;
telnet 35.175.x.x 9997 &lt;BR /&gt;
telnet 54.241.x.x 443 &lt;BR /&gt;
2.So port is allowed but when i run netstat -a 9997 port not shows.&lt;BR /&gt;
3.Splunk service is running in both servers(But when i try to restart, first time it shows error (windows cannot stop splunk forwarder service on local computer Error:1053) and the service gets stopped but iam able to start the service anyway). &lt;BR /&gt;
4.Local Windows firewall is turned off.&lt;BR /&gt;
5.When i checked for the logs from C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log i found the error message 'The TCP output processor has paused the data flow. Forwarding to output group splunkcloud has been blocked for 598307 seconds'&lt;/P&gt;

&lt;P&gt;Gents, can the point no.2 or point no.5 causing the issue. Anyway to fx this?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 17:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431992#M6378</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2019-01-29T17:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431993#M6379</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;maybe the official doc for trouble shooting this could add some value &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Troubleshooting/Cantfinddata"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 19:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431993#M6379</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-29T19:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431994#M6380</link>
      <description>&lt;P&gt;Try running Splunk service as local user instead of specific account.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 19:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431994#M6380</guid>
      <dc:creator>saurabh009</dc:creator>
      <dc:date>2019-01-29T19:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431995#M6381</link>
      <description>&lt;P&gt;No account specified. Changed to local account but no luck&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 20:05:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431995#M6381</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2019-01-29T20:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431996#M6382</link>
      <description>&lt;P&gt;Another observation is:&lt;/P&gt;

&lt;P&gt;The folder &lt;STRONG&gt;100_&lt;EM&gt;CompanyName&lt;/EM&gt;_splunkcloud&lt;/STRONG&gt; is not getting created when installing splunk in the path &lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps\&lt;/CODE&gt;.  I am able to see that folder in the reporting servers. And in that folder &lt;CODE&gt;Pem&lt;/CODE&gt; file, &lt;CODE&gt;ouputs.conf&lt;/CODE&gt; etc. exists.&lt;/P&gt;

&lt;P&gt;This causing the issue?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 22:58:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431996#M6382</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2020-09-29T22:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431997#M6383</link>
      <description>&lt;P&gt;For standard, simple, non-SSL Splunk, you need an &lt;CODE&gt;outputs.conf&lt;/CODE&gt; on the forwarder pointing to the Indexers and port &lt;CODE&gt;9997&lt;/CODE&gt;.  You should be able to &lt;CODE&gt;telnet Your.Indexer.IP.Address 9997&lt;/CODE&gt; and get a login prompt from the forwarder.  If not, something besides Splunk is blocking.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 01:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431997#M6383</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-30T01:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431998#M6384</link>
      <description>&lt;P&gt;@woodcock I think this is causing the issue? Do you have any thoughts on this?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 14:01:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431998#M6384</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2019-01-30T14:01:39Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431999#M6385</link>
      <description>&lt;P&gt;If you are in Splunk Cloud, then support should have given you a &lt;CODE&gt;100_CompanyName_splunkcloud&lt;/CODE&gt; app.&lt;BR /&gt;
If you used competent PS, they should have suggest that you deploy a Deployment Server and given you an app with a &lt;CODE&gt;deploymentclient.conf&lt;/CODE&gt; file to point to your Deployment Server.&lt;/P&gt;

&lt;P&gt;Both apps should go into the &lt;CODE&gt;C:\Program Files\SplunkUniversalForwarder\etc\apps&lt;/CODE&gt; folder.  If you can identify these apps on a working forwarder, just copy them exactly as-is to the non-working forwarder and restart Splunk on the destination forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 15:01:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/431999#M6385</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-30T15:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432000#M6386</link>
      <description>&lt;P&gt;I copied the 100_CompanyName_Splunkcloud folder from the working server and restarted the service still the clients are not reporting&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:01:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432000#M6386</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2020-09-29T23:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432001#M6387</link>
      <description>&lt;P&gt;Can you do the &lt;CODE&gt;telnet&lt;/CODE&gt; test?  Do you get login prompt?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 16:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432001#M6387</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-30T16:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432002#M6388</link>
      <description>&lt;P&gt;I dont know what you mean exactly.&lt;/P&gt;

&lt;P&gt;But iam able to telnet the splunk's public IP over the port 9997. Is that the thing that you are asking for?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 17:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432002#M6388</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2019-01-30T17:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432003#M6389</link>
      <description>&lt;P&gt;Yes.  If you get a prompt, then there is nothing blocking the traffic.  You should be able to see your forwarder with this search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats count WHERE index=_* values(sourcetype) BY host
| search host = "Your HostName OR IP Here"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Jan 2019 17:35:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432003#M6389</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-30T17:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432004#M6390</link>
      <description>&lt;P&gt;Ok. It seems i'm able to get the events by &lt;CODE&gt;IP address&lt;/CODE&gt; but i'm not sure i'm searching in the correct way. I queried in the below format &lt;STRONG&gt;(Source Network Address: *IP Address)&lt;/STRONG&gt;*We generally search for the &lt;CODE&gt;hostnames&lt;/CODE&gt; by using below query &lt;CODE&gt;index=main | stats count by host | sort -count&lt;/CODE&gt;,  May i know how do i search for the events using &lt;CODE&gt;IP address&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;So &lt;STRONG&gt;(Source Network Address: *IP Address)&lt;/STRONG&gt;* is the correct way of checking?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 18:15:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432004#M6390</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2019-01-30T18:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432005#M6391</link>
      <description>&lt;P&gt;I do not understand what you wrote.  Show me your &lt;EM&gt;EXACT&lt;/EM&gt; search strings and prefix that SPL code with a blank line separating it from the rest of your text and indent each line with 4 spaces so that it gets treated as a code block by the markup renderer.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 18:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432005#M6391</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-30T18:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432006#M6392</link>
      <description>&lt;P&gt;Is below query is correct way of searching for the servers by using IP address in splunk console?&lt;BR /&gt;
&lt;STRONG&gt;Source Network Address:   10.36.128.142&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 20:22:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432006#M6392</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2019-01-30T20:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432007#M6393</link>
      <description>&lt;P&gt;I do not know what "splunk console" is.  I do not know what &lt;CODE&gt;Source Network Address: 10.36.128.142&lt;/CODE&gt; syntax means.  The only way for me to figure out is for you to POST YOUR EXACT SEARCH STRING!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 20:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432007#M6393</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-30T20:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432008#M6394</link>
      <description>&lt;P&gt;This the search string Source Network Address: 10.36.128.142&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 20:53:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432008#M6394</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2019-01-30T20:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Client not reporting in Splunk</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432009#M6395</link>
      <description>&lt;P&gt;OK.We found the folder &lt;STRONG&gt;100_CompanyName_splunkcloud&lt;/STRONG&gt; is not getting create when we install the password file and it causes the issue. Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:03:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Client-not-reporting-in-Splunk/m-p/432009#M6395</guid>
      <dc:creator>sugandhakumar</dc:creator>
      <dc:date>2020-09-29T23:03:00Z</dc:date>
    </item>
  </channel>
</rss>

