<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying to view Windows Logs in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81917#M20770</link>
    <description>&lt;P&gt;I'm trying to view Windows Logs. I installed the universal forwarder on the local Windows PC.&lt;BR /&gt;
I configured only for local system, not remote. I added new receiver port 9997 on the server &amp;amp; restarted Splunk.&lt;BR /&gt;
But when I go to Add data from Windows Logs, still asks me to install univ. forwarder and when I got to server, doesn't list the receiver I added. When I try to re-add it, it shows me this:&lt;/P&gt;

&lt;P&gt;"Encountered the following error while trying to save: In handler 'cooked': Failed to create. Configuration for port 9997 already exists."&lt;/P&gt;

&lt;P&gt;Splunk 4.3 Server is running on Linux.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Oct 2012 16:53:47 GMT</pubDate>
    <dc:creator>aalborz</dc:creator>
    <dc:date>2012-10-05T16:53:47Z</dc:date>
    <item>
      <title>Trying to view Windows Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81917#M20770</link>
      <description>&lt;P&gt;I'm trying to view Windows Logs. I installed the universal forwarder on the local Windows PC.&lt;BR /&gt;
I configured only for local system, not remote. I added new receiver port 9997 on the server &amp;amp; restarted Splunk.&lt;BR /&gt;
But when I go to Add data from Windows Logs, still asks me to install univ. forwarder and when I got to server, doesn't list the receiver I added. When I try to re-add it, it shows me this:&lt;/P&gt;

&lt;P&gt;"Encountered the following error while trying to save: In handler 'cooked': Failed to create. Configuration for port 9997 already exists."&lt;/P&gt;

&lt;P&gt;Splunk 4.3 Server is running on Linux.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 16:53:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81917#M20770</guid>
      <dc:creator>aalborz</dc:creator>
      <dc:date>2012-10-05T16:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to view Windows Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81918#M20771</link>
      <description>&lt;P&gt;You cannot configure the inputs on the Splunk server.  YOu'll need to do that on the forwarder located on your windows PC.  Here's what you need to do:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Setupforwardingandreceiving"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Setupforwardingandreceiving&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;1) Enable the receiver on splunk server for port 9997 ( Done )&lt;BR /&gt;
2) Edit outputs.conf on the forwarder to tell it to send to your reciever.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configureforwarderswithoutputs.confd"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Deploy/Configureforwarderswithoutputs.confd&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;3) Configure inputs.conf on the forwarder. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorwindowsdata#Use_inputs.conf_to_configure_event_log_monitoring"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Data/Monitorwindowsdata#Use_inputs.conf_to_configure_event_log_monitoring&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 17:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81918#M20771</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-05T17:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to view Windows Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81919#M20772</link>
      <description>&lt;P&gt;Seems to be too much work to get Windows logs into Splunk!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 20:17:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81919#M20772</guid>
      <dc:creator>aalborz</dc:creator>
      <dc:date>2012-10-05T20:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to view Windows Logs</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81920#M20773</link>
      <description>&lt;P&gt;It's not too bad at all. Steps 2 and 3 are a couple of lines each in two configuration files.  Once you get the hang of where the files are etc...it's smooth sailing.  Then on a larger scales we have the deployment mananger so you can edit something once and push it out to many servers.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2012 20:19:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-view-Windows-Logs/m-p/81920#M20773</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-10-05T20:19:15Z</dc:date>
    </item>
  </channel>
</rss>

