<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Universal Forwarder - Not Forwarding in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616825#M214382</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes it was a DNS issue with the host in question....&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2022 15:40:41 GMT</pubDate>
    <dc:creator>pmacdonald</dc:creator>
    <dc:date>2022-10-12T15:40:41Z</dc:date>
    <item>
      <title>Windows Universal Forwarder - Not Forwarding?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616759#M214359</link>
      <description>&lt;P&gt;I am tying to track down why my Windows Universal forwarder is not forwarding to the Splunk server/index. I can't seem to see anything for example in the past 24 hours and not sure why?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;##&lt;BR /&gt;## SPDX-FileCopyrightText: 2021 Splunk, Inc. &amp;lt;sales@splunk.com&amp;gt;&lt;BR /&gt;## SPDX-License-Identifier: LicenseRef-Splunk-8-2021&lt;BR /&gt;## DO NOT EDIT THIS FILE!&lt;BR /&gt;## Please make all changes to files in $SPLUNK_HOME/etc/apps/Splunk_TA_windows/local.&lt;BR /&gt;## To make changes, copy the section/stanza you want to change from $SPLUNK_HOME/etc/apps/Splunk_TA_windows/default&lt;BR /&gt;## into ../local and edit there.&lt;BR /&gt;##&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;###### OS Logs ######&lt;BR /&gt;[WinEventLog://Application]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = wineventlog&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;renderXml=true&lt;/P&gt;
&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = wineventlog&lt;BR /&gt;start_from = oldest&lt;BR /&gt;current_only = 0&lt;BR /&gt;checkpointInterval = 5&lt;BR /&gt;renderXml=true&lt;/P&gt;
&lt;P&gt;###### Host monitoring ######&lt;BR /&gt;[WinHostMon://Computer]&lt;BR /&gt;interval = 600&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = hostmonitoring&lt;BR /&gt;type = Computer&lt;/P&gt;
&lt;P&gt;[WinHostMon://Process]&lt;BR /&gt;interval = 600&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = hostmonitoring&lt;BR /&gt;type = Process&lt;/P&gt;
&lt;P&gt;[WinHostMon://Processor]&lt;BR /&gt;interval = 600&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = hostmonitoring&lt;BR /&gt;type = Processor&lt;/P&gt;
&lt;P&gt;[WinHostMon://NetworkAdapter]&lt;BR /&gt;interval = 600&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = hostmonitoring&lt;BR /&gt;type = NetworkAdapter&lt;/P&gt;
&lt;P&gt;[WinHostMon://Service]&lt;BR /&gt;interval = 600&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = hostmonitoring&lt;BR /&gt;type = Service&lt;/P&gt;
&lt;P&gt;[WinHostMon://Disk]&lt;BR /&gt;interval = 600&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = hostmonitoring&lt;BR /&gt;type = Disk&lt;/P&gt;
&lt;P&gt;###### Splunk 5.0+ Performance Counters ######&lt;BR /&gt;## CPU&lt;BR /&gt;[perfmon://CPU]&lt;BR /&gt;counters = % Processor Time; % User Time; % Privileged Time; Interrupts/sec; % DPC Time; % Interrupt Time; DPCs Queued/sec; DPC Rate; % Idle Time; % C1 Time; % C2 Time; % C3 Time; C1 Transitions/sec; C2 Transitions/sec; C3 Transitions/sec&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = perfmoncpu&lt;BR /&gt;instances = *&lt;/P&gt;
&lt;P&gt;mode = multikv&lt;BR /&gt;object = Processor&lt;BR /&gt;useEnglishOnly=true&lt;/P&gt;
&lt;P&gt;## Logical Disk&lt;BR /&gt;[perfmon://LogicalDisk]&lt;BR /&gt;counters = % Free Space; Free Megabytes; Current Disk Queue Length; % Disk Time; Avg. Disk Queue Length; % Disk Read Time; Avg. Disk Read Queue Length; % Disk Write Time; Avg. Disk Write Queue Length; Avg. Disk sec/Transfer; Avg. Disk sec/Read; Avg. Disk sec/Write; Disk Transfers/sec; Disk Reads/sec; Disk Writes/sec; Disk Bytes/sec; Disk Read Bytes/sec; Disk Write Bytes/sec; Avg. Disk Bytes/Transfer; Avg. Disk Bytes/Read; Avg. Disk Bytes/Write; % Idle Time; Split IO/Sec&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = perfmonlogicaldisk&lt;BR /&gt;instances = *&lt;BR /&gt;interval = 60&lt;BR /&gt;mode = multikv&lt;BR /&gt;object = LogicalDisk&lt;BR /&gt;useEnglishOnly=true&lt;/P&gt;
&lt;P&gt;## Physical Disk&lt;BR /&gt;[perfmon://PhysicalDisk]&lt;BR /&gt;counters = Current Disk Queue Length; % Disk Time; Avg. Disk Queue Length; % Disk Read Time; Avg. Disk Read Queue Length; % Disk Write Time; Avg. Disk Write Queue Length; Avg. Disk sec/Transfer; Avg. Disk sec/Read; Avg. Disk sec/Write; Disk Transfers/sec; Disk Reads/sec; Disk Writes/sec; Disk Bytes/sec; Disk Read Bytes/sec; Disk Write Bytes/sec; Avg. Disk Bytes/Transfer; Avg. Disk Bytes/Read; Avg. Disk Bytes/Write; % Idle Time; Split IO/Sec&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = perfmonphysicaldisk&lt;BR /&gt;instances = *&lt;BR /&gt;interval = 60&lt;BR /&gt;mode = multikv&lt;BR /&gt;object = PhysicalDisk&lt;BR /&gt;useEnglishOnly=true&lt;/P&gt;
&lt;P&gt;## Memory&lt;BR /&gt;[perfmon://Memory]&lt;BR /&gt;counters = Page Faults/sec; Available Bytes; Committed Bytes; Commit Limit; Write Copies/sec; Transition Faults/sec; Cache Faults/sec; Demand Zero Faults/sec; Pages/sec; Pages Input/sec; Page Reads/sec; Pages Output/sec; Pool Paged Bytes; Pool Nonpaged Bytes; Page Writes/sec; Pool Paged Allocs; Pool Nonpaged Allocs; Free System Page Table Entries; Cache Bytes; Cache Bytes Peak; Pool Paged Resident Bytes; System Code Total Bytes; System Code Resident Bytes; System Driver Total Bytes; System Driver Resident Bytes; System Cache Resident Bytes; % Committed Bytes In Use; Available KBytes; Available MBytes; Transition Pages RePurposed/sec; Free &amp;amp; Zero Page List Bytes; Modified Page List Bytes; Standby Cache Reserve Bytes; Standby Cache Normal Priority Bytes; Standby Cache Core Bytes; Long-Term Average Standby Cache Lifetime (s)&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = perfmonmemory&lt;BR /&gt;interval = 60&lt;BR /&gt;mode = multikv&lt;BR /&gt;object = Memory&lt;BR /&gt;useEnglishOnly=true&lt;/P&gt;
&lt;P&gt;## Network&lt;BR /&gt;[perfmon://Network]&lt;BR /&gt;counters = Bytes Total/sec; Packets/sec; Packets Received/sec; Packets Sent/sec; Current Bandwidth; Bytes Received/sec; Packets Received Unicast/sec; Packets Received Non-Unicast/sec; Packets Received Discarded; Packets Received Errors; Packets Received Unknown; Bytes Sent/sec; Packets Sent Unicast/sec; Packets Sent Non-Unicast/sec; Packets Outbound Discarded; Packets Outbound Errors; Output Queue Length; Offloaded Connections; TCP Active RSC Connections; TCP RSC Coalesced Packets/sec; TCP RSC Exceptions/sec; TCP RSC Average Packet Size&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = perfmonnetwork&lt;BR /&gt;instances = *&lt;BR /&gt;interval = 60&lt;BR /&gt;mode = multikv&lt;BR /&gt;object = Network Interface&lt;BR /&gt;useEnglishOnly=true&lt;/P&gt;
&lt;P&gt;## Process&lt;BR /&gt;[perfmon://Process]&lt;BR /&gt;counters = % Processor Time; % User Time; % Privileged Time; Virtual Bytes Peak; Virtual Bytes; Page Faults/sec; Working Set Peak; Working Set; Page File Bytes Peak; Page File Bytes; Private Bytes; Thread Count; Priority Base; Elapsed Time; ID Process; Creating Process ID; Pool Paged Bytes; Pool Nonpaged Bytes; Handle Count; IO Read Operations/sec; IO Write Operations/sec; IO Data Operations/sec; IO Other Operations/sec; IO Read Bytes/sec; IO Write Bytes/sec; IO Data Bytes/sec; IO Other Bytes/sec; Working Set - Private&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = perfmonprocess&lt;BR /&gt;instances = *&lt;BR /&gt;interval = 60&lt;BR /&gt;mode = multikv&lt;BR /&gt;object = Process&lt;BR /&gt;useEnglishOnly=true&lt;/P&gt;
&lt;P&gt;## ProcessInformation&lt;BR /&gt;[perfmon://ProcessorInformation]&lt;BR /&gt;counters = % Processor Time; Processor Frequency&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = perfmonprocessinfo&lt;BR /&gt;instances = *&lt;BR /&gt;interval = 60&lt;BR /&gt;mode = multikv&lt;BR /&gt;object = Processor Information&lt;BR /&gt;useEnglishOnly=true&lt;/P&gt;
&lt;P&gt;## System&lt;BR /&gt;[perfmon://System]&lt;BR /&gt;counters = File Read Operations/sec; File Write Operations/sec; File Control Operations/sec; File Read Bytes/sec; File Write Bytes/sec; File Control Bytes/sec; Context Switches/sec; System Calls/sec; File Data Operations/sec; System Up Time; Processor Queue Length; Processes; Threads; Alignment Fixups/sec; Exception Dispatches/sec; Floating Emulations/sec; % Registry Quota In Use&lt;BR /&gt;disabled = 0&lt;BR /&gt;index = perfmonsystem&lt;BR /&gt;instances = *&lt;BR /&gt;interval = 60&lt;BR /&gt;mode = multikv&lt;BR /&gt;object = System&lt;BR /&gt;useEnglishOnly=true&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 14:51:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616759#M214359</guid>
      <dc:creator>pmacdonald</dc:creator>
      <dc:date>2022-10-12T14:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarder - Not Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616812#M214377</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249987"&gt;@pmacdonald&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to troubleshhot your connection.&lt;/P&gt;&lt;P&gt;At first, have you results running&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=&amp;lt;your_host&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;or&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=* host=&amp;lt;your_host&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;?&lt;/P&gt;&lt;P&gt;if yes the connection is ok and there's some input problem, if not, you have to check the connection between the forwarder and Indexers, e.g. using telnet.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 12:15:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616812#M214377</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-12T12:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarder - Not Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616825#M214382</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes it was a DNS issue with the host in question....&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 15:40:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616825#M214382</guid>
      <dc:creator>pmacdonald</dc:creator>
      <dc:date>2022-10-12T15:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Universal Forwarder - Not Forwarding</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616917#M214399</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249987"&gt;@pmacdonald&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 06:27:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Windows-Universal-Forwarder-Not-Forwarding/m-p/616917#M214399</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-13T06:27:23Z</dc:date>
    </item>
  </channel>
</rss>

