Getting Data In

Universal forwarder not forwarding to other linux/windows

rakeshksingh
New Member

I have installed Uf in one linux and splunk instance in another linux/windows. While trying to configure , uf is not forwarding data to linux/windows splunk,ping is working fine.

Could you please help me on this.

0 Karma

skulk
Explorer

Hi!
1) Try to restart frowarder
2) Check index = _internal for forwarder logs existence

If it is not working, please provide us full your outputs.conf config

0 Karma

robgora_deloitt
Path Finder

I would also check the _internal on the Splunk Indexer to see if you can see the UF host connecting to the Indexer. Is the host anywhere in the logs? It could be that the server is connecting but your app has an issue with it's input.conf

0 Karma

rakeshksingh
New Member

i have configured outputs.conf (ip:9997) in linux universal forwarder and at splunk instances configured receiver as 9997. but still not working.
i have stop firewall with sudo ufw disable and tried. but still not working

0 Karma

robgora_deloitt
Path Finder

Have you validated that your Splunk indexer is listening on port 9997 and that your UF is configured in the outputs.conf to send to your indexer over port 9997? I would also validate that you have port 9997 open in your firewall as well. You can validate this with telnet.

0 Karma

rakeshksingh
New Member

i have configured outputs.conf (ip:9997) in linux universal forwarder and at splunk instances configured receiver as 9997. but still not working.
i have stop firewall with sudo ufw disable and tried. but still not working

0 Karma

rakeshksingh
New Member

its working fine with heavy forwarder but not with universal forwarder

0 Karma

robgora_deloitt
Path Finder

Can you telnet over port 9997? Also have you checked the physical firewall to ensure that the ports are open?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...