<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Forwarder can't send data to enterprise in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689929#M114809</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268778"&gt;@Cyner__&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first did you followed the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Data/Usingforwardingagents" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Data/Usingforwardingagents&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;In other words:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;did you checked the open route between UF and Splunk on port 9997 (default)? you can do this using telnet.&lt;/LI&gt;&lt;LI&gt;did you enabled receiving in Splunk Enterprise ? [Settings &amp;gt; Forwardring and Receiving &amp;gt; Receiving]&lt;/LI&gt;&lt;LI&gt;did you enabled forwarding in Universal Forwarder?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;When you did the above steps, you can check the connection using the following search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=your_client_host)&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2024 08:35:25 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-06-07T08:35:25Z</dc:date>
    <item>
      <title>Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689926#M114807</link>
      <description>&lt;P&gt;I am newbie to splunk. Any help is appreciated&lt;/P&gt;&lt;P&gt;So I have an splunk enterprise in my windows computer. and splunk forwarder in a ubuntu VPS server with a cowrie honeypot built in. So my problem is when i try to ping test my local computer with VPS server , i have %100 packet loss.&lt;/P&gt;&lt;P&gt;Also splunkd log file is full of "cooked connection to "my-local-ip" timed out and&lt;/P&gt;&lt;P&gt;... blocked nfor blocked_seconds=3000. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;/P&gt;&lt;P&gt;errors&lt;/P&gt;&lt;P&gt;Thanks for helping. I am waiting for your response&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 08:16:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689926#M114807</guid>
      <dc:creator>Cyner__</dc:creator>
      <dc:date>2024-06-07T08:16:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689927#M114808</link>
      <description>&lt;P&gt;Also i can't find anything in the Splunk Enterprise. Nothing in forwarder management section and no data whatsoever&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 08:30:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689927#M114808</guid>
      <dc:creator>Cyner__</dc:creator>
      <dc:date>2024-06-07T08:30:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689929#M114809</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268778"&gt;@Cyner__&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first did you followed the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.1/Data/Usingforwardingagents" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.1/Data/Usingforwardingagents&lt;/A&gt;&amp;nbsp;?&lt;/P&gt;&lt;P&gt;In other words:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;did you checked the open route between UF and Splunk on port 9997 (default)? you can do this using telnet.&lt;/LI&gt;&lt;LI&gt;did you enabled receiving in Splunk Enterprise ? [Settings &amp;gt; Forwardring and Receiving &amp;gt; Receiving]&lt;/LI&gt;&lt;LI&gt;did you enabled forwarding in Universal Forwarder?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;When you did the above steps, you can check the connection using the following search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal host=your_client_host)&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 08:35:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689929#M114809</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-07T08:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689942#M114810</link>
      <description>&lt;P&gt;Thanks for the help&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But my problem is still occurs.&lt;/P&gt;&lt;P&gt;When i use telnet with 9997 port to my computer (tried both private and public ip) telnet runs "connection timed out" error.&lt;/P&gt;&lt;P&gt;i already enabled receiving.&lt;/P&gt;&lt;P&gt;I don't know if i enabled forwarder or not bu i Start'ed it with command and configured output and input file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is inputs.conf:&lt;/P&gt;&lt;P&gt;[monitor:///home/cowrie/cowrie/var/log/cowrie/cowrie.json]&lt;BR /&gt;index = cowrie&lt;BR /&gt;sourcetype = json&lt;BR /&gt;disabled = false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is output.conf:&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup = default-autolb-group&lt;/P&gt;&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;disabled = false&lt;BR /&gt;server = my-private-ip:9997&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry if i missed something as i said im both new to linux and splunk&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 09:13:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689942#M114810</guid>
      <dc:creator>Cyner__</dc:creator>
      <dc:date>2024-06-07T09:13:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689944#M114811</link>
      <description>&lt;P&gt;ah also when i clicked "data summary" button from splunk enterprise web,&amp;nbsp; i only see "waiting for results"&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 09:16:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689944#M114811</guid>
      <dc:creator>Cyner__</dc:creator>
      <dc:date>2024-06-07T09:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689946#M114812</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268778"&gt;@Cyner__&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you should run the telnet from the client, not from the Server:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;telnet my-private-ip 9997&lt;/LI-CODE&gt;&lt;P&gt;If it doesn't answer there's something in the middle (e.g. personal firewalls) that block the connection.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 09:21:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689946#M114812</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-07T09:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689949#M114813</link>
      <description>&lt;P&gt;Ok. Now i run the telnet &amp;lt;my-forwarders-ip&amp;gt; 9997 command from my windows pc&lt;/P&gt;&lt;P&gt;The result is "could not open connection to the host. port 9997 .connect failed"&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i run for both private ip and public ip.&lt;/P&gt;&lt;P&gt;My windows firewall is disabled and my forwarders server doesn't even have firewall installed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 09:49:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689949#M114813</guid>
      <dc:creator>Cyner__</dc:creator>
      <dc:date>2024-06-07T09:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689952#M114814</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i think i found my problem. I don't have open 9997 port on my forwarder server i guess.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cyner___0-1717754080314.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/31219i9ED30073CD0839FB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Cyner___0-1717754080314.png" alt="Cyner___0-1717754080314.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;this is the screenshot. How can i open the 9997 port&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 09:59:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689952#M114814</guid>
      <dc:creator>Cyner__</dc:creator>
      <dc:date>2024-06-07T09:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689967#M114817</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268778"&gt;@Cyner__&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;port 9997 must be opened on the Spunk Enterprise, not on the client, you can open the port in [Settings &amp;gt; Forwarding and Receiving &amp;gt; Receiving].&lt;/P&gt;&lt;P&gt;Infact the telnet test must be done on the client not from the Splunk Server.&lt;/P&gt;&lt;P&gt;Did you completed al the steps described in the document or in my previous answer?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 11:57:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689967#M114817</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-07T11:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689969#M114818</link>
      <description>&lt;P&gt;Hi.&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes i did all. what do you mean by client do you mean the server with forwarder or splunk enterprise ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and when i try to telnet the splunk server via forwarder server "i think its client" connection always times out.&lt;/P&gt;&lt;P&gt;i saw my splunk server (my computer i guess) doesn't have any inputs.conf at directory C:\Program Files\Splunk\etc\system\local path.&amp;nbsp;&lt;/P&gt;&lt;P&gt;what should i do?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 12:12:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689969#M114818</guid>
      <dc:creator>Cyner__</dc:creator>
      <dc:date>2024-06-07T12:12:42Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder can't send data to enterprise</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689978#M114820</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268778"&gt;@Cyner__&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to enable receiving on Splunk Enterprise,&lt;/P&gt;&lt;P&gt;then you have to check the route from the Universal Forwarder on port 9997 to the Spunk Enterprise (using telnet),&lt;/P&gt;&lt;P&gt;then you have to configure your outputs.con (as described in the above link) in the Universal Forwarder.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 12:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-can-t-send-data-to-enterprise/m-p/689978#M114820</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-06-07T12:56:24Z</dc:date>
    </item>
  </channel>
</rss>

