All Apps and Add-ons

Splunk Universal Forwarder won't forward events(or indexer won't receive)

shahara
New Member

Hi All,

I'm currently implementing a new installation of Splunk.
Single-Server-Scenario server that will have forwarders forwarding data into it.
I'm trying to install the Windows Infrastructure App.
I began by installing the Universal Forwarders and setting a sendtoindexer app.
Here are the configurations in the outputs.conf of the sendtoindexer app:

[tcpout]
defaultGroup = splunkindexers

[tcpout:splunkindexers]
server = splunkprod:9997

[tcpout-server://splunkprod:9997]


Nothing appears in the relevant indexes and i get the following error when i go into the Splunk system activity page:

04-20-2015 15:10:50.415 +0300 ERROR TcpOutputFd - Connection to host=192.168.XX.XXX:9997 failed

Please assist ASAP, any feedback will be helpful...

Thanks a lot!!!
Shahar

0 Karma

malmoore
Splunk Employee
Splunk Employee

Confirm that Windows Firewall isn't silently eating packets on both the client and the server.

0 Karma

shahara
New Member

Of course, It's configured to receive on this port.
Additionally, when i use telnet to the splunk server using 9997 i get an answer.

Thanks,
Shahar

0 Karma

schose
Builder

Hi,

is the Splunk server configured for receiving events?! check settings->forwarding and receiving->configure receiving ...

Can you establish a tcp connection from client to server on tcp/9997 (from client: telnet server 9997)

Cheers,

Andreas

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...