Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Univeral forwarder not forwarding

$
0
0

I have a problem with a universal forwarder as i configured on a domain controller to use with splunk app for active directory. The forwarder is not forwarding anything. what i have done so far: 1. installed the forwarder to gather remote data and used an domain admin account. i did not check any of the checkboxes during the installation. but i typed in the reciving indexer when asked for 2. i have downloaded and copied the folders Splunk_TA_windows, TA-DNSServer-NT6 and TA-DomainController-NT6 to the apps directory on the universal forwarder 3. I have put a inputs.conf file under Splunk_TA_windowslocal folder and then restarted the forwarder

But noting is sent to indexer. I am sure that there is no firewall or anything like that blocking because i first installed the forwarder as usual and checked the security log input in the installation wizard (after reading the manual about splunk app for active directory i uninstalled it) and saw that events where sent to and recieved by the indexer.


Viewing all articles
Browse latest Browse all 13053

Trending Articles