Getting Data In

Universal forwarder not forwarding to other linux/windows

rakeshksingh
New Member

I have installed Uf in one linux and splunk instance in another linux/windows. While trying to configure , uf is not forwarding data to linux/windows splunk,ping is working fine.

Could you please help me on this.

0 Karma

skulk
Explorer

Hi!
1) Try to restart frowarder
2) Check index = _internal for forwarder logs existence

If it is not working, please provide us full your outputs.conf config

0 Karma

robgora_deloitt
Path Finder

I would also check the _internal on the Splunk Indexer to see if you can see the UF host connecting to the Indexer. Is the host anywhere in the logs? It could be that the server is connecting but your app has an issue with it's input.conf

0 Karma

rakeshksingh
New Member

i have configured outputs.conf (ip:9997) in linux universal forwarder and at splunk instances configured receiver as 9997. but still not working.
i have stop firewall with sudo ufw disable and tried. but still not working

0 Karma

robgora_deloitt
Path Finder

Have you validated that your Splunk indexer is listening on port 9997 and that your UF is configured in the outputs.conf to send to your indexer over port 9997? I would also validate that you have port 9997 open in your firewall as well. You can validate this with telnet.

0 Karma

rakeshksingh
New Member

i have configured outputs.conf (ip:9997) in linux universal forwarder and at splunk instances configured receiver as 9997. but still not working.
i have stop firewall with sudo ufw disable and tried. but still not working

0 Karma

rakeshksingh
New Member

its working fine with heavy forwarder but not with universal forwarder

0 Karma

robgora_deloitt
Path Finder

Can you telnet over port 9997? Also have you checked the physical firewall to ensure that the ports are open?

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...