I have Splunk set up on Windows 7. Set to receive on port 9997.
I have Splunk Universal Forwarder on Ubuntu set to forward to my Windows 7 Splunk instance on port 9997
I take a trace on my Windows machine and see traffic on port 9997 from the Ubuntu machine
However, the Windows never responds.
Any assistance would be appreciated
Figured it out. My Windows Firewall was enabled.
Disabled that and all worked
This is the same question as How to activate forward-server. There is a nice set of suggestions there.