Hi,
I have Splunk 5.0.5 installed on a Windows OS 2012
I have a windows 2008 64-bit with splunkforwarder-6.1.2-213098-x64-release.msi bits installed but it is not forwarding data to Splunk.
Any clues on what could be wrong?
- I checked that the firewall is not blocking the connection.
- I checked on Splunk that it is accepting data on port 9997
- The event logs are not displaying error messages on either server.
Does anyone know what else I need to check?
Thanks,
MCO
One of the first things I would check is the time on the server. This happened to me many times and I realized that the time on my forwarder was wrong which is why I was not seeing any data flowing to my indexer. Check out the link below and that might help you out.