Refine your search:

Splunk New User here.

I am having trouble getting forwarding and receiving working to any degree.

On the receiver I have enabled forwarding and assigned the listening port. Used the default 9997.

On the forwarder I have enabled forwarding and pointed the forwarder to the receivers ip address along with the correct port.

I am seeing nothing in the logs to indicate that the forwarder is forwarding.

My input.cfg is empty except for the hostname ( found on path C:\Program Files\Splunk\etc\system\local). This is the case for both forwarder and receiver.

What am I doing wrong?

Edit: Receiver is Win 7 64bit Forwarder is Windows Server 64x 2008

I have enabled wmi and logs in under the data input control panel.

asked 07 Jan '11, 22:24

bearrito's gravatar image

bearrito
111
accept rate: 0%


2 Answers:

Which splunk version are you using? 4.0.x/4.1.x requires restart of forwarder after configuring forwarder. Please try restarting forwarder.

link

answered 08 Jan '11, 00:34

jkerai's gravatar image

jkerai
1492
accept rate: 25%

i know its a little late... but here's my solution... same system setup, trying to forward one window's event log to another server.

Turns out, port 9997 is not configured in Win2k8 firewall. So open up your Computer-Manager, and find the rule for Splunkd... look for the entry which already has port 8000 opened, and append 9997 to this entry.

Restart splunk, and everything should work.

link

answered 21 Apr '11, 03:30

klee310's gravatar image

klee310
133112
accept rate: 0%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×635
×109

Asked: 07 Jan '11, 22:24

Seen: 2,080 times

Last updated: 21 Apr '11, 03:30

Copyright © 2005-2012 Splunk Inc. All rights reserved.