Getting Data In

Why am I getting "Connection to host=:9997 failed" after configuring a universal forwarder on Linux?

nitheeshp86
New Member

I have configured a universal forwarder on one of our Linux systems. When i check the logs it shows

Connection to host=192.168.2.1:9997 failed (where 192.168.2.1 is splunk enterprise ) server.

I have referred to this solution but didn't work http://answers.splunk.com/answers/49833/splunk-forwarder-connection-refused-from-splunk-indexer.html

0 Karma

MuS
Legend

hi nitheeshp86,

do the usual troubleshooting like:

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...