I have setup port 9990 as a TCP Data Input, but our Splunk server is not accepting connections from that port. It works from localhost on the server itself, but not from any other machine even on the same subnet. There is no firewall dropping the traffic. Any idea what may be wrong?
Works from localhost:
[root@tdcvlog01 ~]# telnet 127.0.0.1 9990
Trying 127.0.0.1...
Connected to 127.0.0.1.
Escape character is '^]'.
^]
telnet> quit
Connection closed.
Not from external hosts:
C:\Users\splunk>telnet x.x.x.x 9990
Connecting To x.x.x.x...Could not open connection to the host, on port 9990: Connect failed
[root@tdcvlog01 ~]# netstat -ntap
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN 1087/splunkd
tcp 0 0 0.0.0.0:111 0.0.0.0:* LISTEN 1205/rpcbind
tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 1479/sshd
tcp 0 0 0.0.0.0:52502 0.0.0.0:* LISTEN 1223/rpc.statd
tcp 0 0 127.0.0.1:631 0.0.0.0:* LISTEN 1359/cupsd
tcp 0 0 0.0.0.0:8089 0.0.0.0:* LISTEN 1087/splunkd
tcp 0 0 127.0.0.1:25 0.0.0.0:* LISTEN 1563/master
tcp 0 0 0.0.0.0:8000 0.0.0.0:* LISTEN 1167/python
tcp 0 0 0.0.0.0:514 0.0.0.0:* LISTEN 1087/splunkd
tcp 0 0 0.0.0.0:9990 0.0.0.0:* LISTEN 1087/splunkd
tcp 0 0 0.0.0.0:5672 0.0.0.0:* LISTEN 1606/qpidd
... View more