<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Universal Forwarder 9.1.3 not connecting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-9-1-3-not-connecting/m-p/688064#M114603</link>
    <description>&lt;P&gt;Hey all,&amp;nbsp; I recently upgraded our Splunk server to 9.1.3.&amp;nbsp; I have a single UF running 8.2 which connects, however my newly deployed 9.1.3 forwarder on server 2 (Windows Server) doesn't connect.&amp;nbsp; This is net new and has never connected.&amp;nbsp; I am seeing mixed info on whether or not SSL certs need to be configured on the forwarder.&amp;nbsp; I see the UF talking to our Enterprise server on port 9997.&amp;nbsp; I am using CA signed certs on the Slunk server and default certificates on the server which uses the UF.&amp;nbsp; &amp;nbsp;Can anyone point me in the right direction to get this working?&amp;nbsp; The output.conf is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[tcpout]
defaultGroup=default-autolb-group

[tcpout:default-autolb-group]
server=&amp;lt;SPLUNK_IP_SERVER&amp;gt;:9997
useSSL=false

[tcpout-server://&amp;lt;SPLUNK_IP_SERVER&amp;gt;:9997]&lt;/LI-CODE&gt;</description>
    <pubDate>Mon, 20 May 2024 20:34:59 GMT</pubDate>
    <dc:creator>cmeyer</dc:creator>
    <dc:date>2024-05-20T20:34:59Z</dc:date>
    <item>
      <title>Universal Forwarder 9.1.3 not connecting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-9-1-3-not-connecting/m-p/688064#M114603</link>
      <description>&lt;P&gt;Hey all,&amp;nbsp; I recently upgraded our Splunk server to 9.1.3.&amp;nbsp; I have a single UF running 8.2 which connects, however my newly deployed 9.1.3 forwarder on server 2 (Windows Server) doesn't connect.&amp;nbsp; This is net new and has never connected.&amp;nbsp; I am seeing mixed info on whether or not SSL certs need to be configured on the forwarder.&amp;nbsp; I see the UF talking to our Enterprise server on port 9997.&amp;nbsp; I am using CA signed certs on the Slunk server and default certificates on the server which uses the UF.&amp;nbsp; &amp;nbsp;Can anyone point me in the right direction to get this working?&amp;nbsp; The output.conf is as follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[tcpout]
defaultGroup=default-autolb-group

[tcpout:default-autolb-group]
server=&amp;lt;SPLUNK_IP_SERVER&amp;gt;:9997
useSSL=false

[tcpout-server://&amp;lt;SPLUNK_IP_SERVER&amp;gt;:9997]&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 20 May 2024 20:34:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-9-1-3-not-connecting/m-p/688064#M114603</guid>
      <dc:creator>cmeyer</dc:creator>
      <dc:date>2024-05-20T20:34:59Z</dc:date>
    </item>
  </channel>
</rss>

