Quantcast
Channel: Questions in topic: "universal-forwarder"
Viewing all articles
Browse latest Browse all 1551

Universal forwarder (Windows) does not send logs even though "active"

$
0
0
Hi Folks, I am testing log forwarding using universal forwarder from Windows to Splunk but can't seem to receive any logs. My test environment has Splunk Enterprise OVA (standalone) as server and Windows 2012 (with universal forwarder) as client. Steps i followed (not necessarily in that order): On Windows client (Universal forwarder): * Installed Universal forwarder * configured as deployment client * Added firewall rule to allow destination port 9997 * checked using "splunk list forward-server" to confirm server is listed in "active" section On Splunk OVA enterprise server * Configured listening on port 9997 using web console * Added forwarder input using Settings -> "Data Inputs" -> "Forwarded Inputs" -> "Windows Event Logs" (could see my desired deployment client in the list). Selected Application, security & system events * Stopped iptables service (just to ensure its not blocking traffic) * Followed [this][1] link to receive logs from forwarder Testing: * created user in windows (client) and checked local event logs. Local log can be seen in "Security" events * Ran search in server (web console) to see this event. It says "no events found" for the specific index [1]: https://answers.splunk.com/answers/49833/splunk-forwarder-connection-refused-from-splunk-indexer.html

Viewing all articles
Browse latest Browse all 1551

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>