<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic port connectivity issue &amp;quot;Connection refused&amp;quot; in Security</title>
    <link>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134741#M4121</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;We are facing port connectivity issue since 5th Sep 2014 between indexer and forwarder :-&lt;/P&gt;

&lt;P&gt;$ telnet forwarder IP port&lt;BR /&gt;
Trying forwarder IP...&lt;BR /&gt;
telnet: connect to address forwarder IP: Connection refused&lt;BR /&gt;
telnet: Unable to connect to remote host: Connection refused&lt;/P&gt;

&lt;P&gt;It is throwing same error while checking connection from forwarder to indexer :-&lt;/P&gt;

&lt;P&gt;$ telnet indexer port&lt;BR /&gt;
Trying indexer IP...&lt;BR /&gt;
telnet: connect to address indexer IP: Connection refused&lt;BR /&gt;
telnet: Unable to connect to remote host: Connection refused&lt;/P&gt;

&lt;P&gt;Please suggest.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 22 Sep 2014 11:28:15 GMT</pubDate>
    <dc:creator>seema2502</dc:creator>
    <dc:date>2014-09-22T11:28:15Z</dc:date>
    <item>
      <title>port connectivity issue "Connection refused"</title>
      <link>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134741#M4121</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;We are facing port connectivity issue since 5th Sep 2014 between indexer and forwarder :-&lt;/P&gt;

&lt;P&gt;$ telnet forwarder IP port&lt;BR /&gt;
Trying forwarder IP...&lt;BR /&gt;
telnet: connect to address forwarder IP: Connection refused&lt;BR /&gt;
telnet: Unable to connect to remote host: Connection refused&lt;/P&gt;

&lt;P&gt;It is throwing same error while checking connection from forwarder to indexer :-&lt;/P&gt;

&lt;P&gt;$ telnet indexer port&lt;BR /&gt;
Trying indexer IP...&lt;BR /&gt;
telnet: connect to address indexer IP: Connection refused&lt;BR /&gt;
telnet: Unable to connect to remote host: Connection refused&lt;/P&gt;

&lt;P&gt;Please suggest.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 11:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134741#M4121</guid>
      <dc:creator>seema2502</dc:creator>
      <dc:date>2014-09-22T11:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: port connectivity issue "Connection refused"</title>
      <link>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134742#M4122</link>
      <description>&lt;P&gt;Well uh...firewall problems? It's really impossible to say anything more without more details. What happened on September 5th that caused this issue to start occurring? &lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 12:05:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134742#M4122</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-09-22T12:05:50Z</dc:date>
    </item>
    <item>
      <title>Re: port connectivity issue "Connection refused"</title>
      <link>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134743#M4123</link>
      <description>&lt;P&gt;Not wishing to seem dismissive, but that does not sound like a fault within the Splunk realm.  It is a network infrastructure problem of some sort, but beyond that any assistance that might be suggested is of a network and systems administration nature, and requires a lot more knowledge of your infrastructure as a whole.&lt;/P&gt;

&lt;P&gt;Your example commands and responses indicate a Unix type platform, and if that is a common Linux distribution, then the command&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sudo netstat -pant | grep -i listen
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;on the indexer and on the forwarder should at least give you some indication of the port statuses on each.  Really, though, the topic of network fault disagnosis is well outside this forum.  Provided Splunk is running all other questions really fall to matters of administration like changes of IP addresses, on-server firewalling - &lt;CODE&gt;iptables&lt;/CODE&gt; - and network firewalls or faults.  You would be better served treating it, in the first instance, as a generic service connection fault and taking your question to a more appropriate board.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 12:11:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134743#M4123</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2014-09-22T12:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: port connectivity issue "Connection refused"</title>
      <link>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134744#M4124</link>
      <description>&lt;P&gt;Hi Ayn,&lt;/P&gt;

&lt;P&gt;Please refer below link for what changed on September 5th.&lt;BR /&gt;
&lt;A href="http://answers.splunk.com/answers/169028/licensing-window-alerts-on-my-indexer-caused-splun.html"&gt;http://answers.splunk.com/answers/169028/licensing-window-alerts-on-my-indexer-caused-splun.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 13:43:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134744#M4124</guid>
      <dc:creator>seema2502</dc:creator>
      <dc:date>2014-09-22T13:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: port connectivity issue "Connection refused"</title>
      <link>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134745#M4125</link>
      <description>&lt;P&gt;Hi grijhwani,&lt;BR /&gt;
We also thought that this issue is related to network but we contacted network team they have responded like :-&lt;BR /&gt;
"Connection refused" means that destination server is not listening on particular port. This is not a NW/FW issue. Application that would normaly respond on those ports is not running or malfunctioning."&lt;/P&gt;

&lt;P&gt;when we tried the mentioned command sudo netstat -pant | grep -i listen we received "xyz is not in the sudoers file.  This incident will be reported."&lt;/P&gt;

&lt;P&gt;Please suggest.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 14:00:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134745#M4125</guid>
      <dc:creator>seema2502</dc:creator>
      <dc:date>2014-09-22T14:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: port connectivity issue "Connection refused"</title>
      <link>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134746#M4126</link>
      <description>&lt;P&gt;I was assuming that you as you were attempting to administer Splunk that you were also an administrator of the system running Splunk.  If you are not then you need to hand the problem to whoever is, since they should have the experience and the authority needed on the servers to investigate it.&lt;/P&gt;

&lt;P&gt;As for the network group's reply, I find that tends to be the stock answer from any network admin until you are waving empirical evidence under his nose.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2014 15:06:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134746#M4126</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2014-09-22T15:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: port connectivity issue "Connection refused"</title>
      <link>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134747#M4127</link>
      <description>&lt;P&gt;hi  grijhwani yes i am the adminstrator for our splunk sandbox and do have command line access as well.&lt;/P&gt;

&lt;P&gt;The System Admin who manages the linux VM that will push into my Splunk instance said he was seeing firewall issues.&lt;/P&gt;

&lt;P&gt;On my splunk instance, do i need to start any listeners or anything like that on ports 8088 and 9997?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2018 22:55:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/port-connectivity-issue-quot-Connection-refused-quot/m-p/134747#M4127</guid>
      <dc:creator>dchima</dc:creator>
      <dc:date>2018-10-24T22:55:56Z</dc:date>
    </item>
  </channel>
</rss>

