<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder not sending data - timed out in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131359#M27004</link>
    <description>&lt;P&gt;had the same problem, couldnt connect to indexer&lt;BR /&gt;
in windows for universal forwarder installation ( 5.0.4) please check the files in:&lt;BR /&gt;
path /SplunkUniversalForwarder/etc/system/local &lt;BR /&gt;
replace the  config files under  with those from:&lt;BR /&gt;
path /SplunkUniversalForwarder/etc/apps/Windows/local &lt;BR /&gt;
restart splunkforwarder:&lt;BR /&gt;
splunk restart&lt;/P&gt;

&lt;P&gt;it should get connected&lt;BR /&gt;
in splunk host i can see the forwarder has been connected and it has send logs. i had activated some advanced audit features.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Dec 2013 10:20:57 GMT</pubDate>
    <dc:creator>Akili</dc:creator>
    <dc:date>2013-12-24T10:20:57Z</dc:date>
    <item>
      <title>Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131353#M26998</link>
      <description>&lt;P&gt;I've installed a universal forwarder on a linux box and configured it, but I'm getting the following errors.  I'm running 5.0.1 and the indexer is currently listening on 9997: &lt;/P&gt;

&lt;P&gt;From indexer:&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 14:02:50.585 -0800 ERROR TcpInputProc - Error encountered for connection from src=xx.xx.xx.xx:60599. Timeout &lt;/P&gt;

&lt;P&gt;From forwarder: &lt;BR /&gt;
11-05-2013 20:23:49.189 -0500 INFO BatchReader - State transitioning from 2 to 0 (initOrResume).&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:23:49.475 -0500 WARN TcpOutputProc - Connected to idx=xx.xx.xx.xx:9997. Not using ACK.&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:24:06.849 -0500 ERROR AuthenticationManagerSplunk - Login failed. Incorrect login for user: admin&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:37:09.152 -0500 WARN TcpOutputProc - Raw connection to ip=xx.xx.xx.xx:9997 timed out&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:37:09.152 -0500 INFO TcpOutputProc - Detected connection to =xx.xx.xx.xx:9997 closed&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:37:09.152 -0500 INFO TcpOutputProc - Will close stream to current indexer   xx.xx.xx.xx:9997&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:37:09.153 -0500 INFO TcpOutputProc - Closing stream for idx==xx.xx.xx.xx:9997&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:37:29.621 -0500 WARN TcpOutputProc - Cooked connection to ip=xx.xx.xx.xx:9997 timed   out&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:37:49.155 -0500 WARN TcpOutputProc - Connected to idx=xx.xx.xx.xx:9997. Not using ACK.&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:42:09.152 -0500 WARN TcpOutputProc - Shutdown timed out for xx.xx.xx.xx:9997&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:50:39.168 -0500 WARN TcpOutputProc - Raw connection to ip=xx.xx.xx.xx:9997 timed out&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:50:39.168 -0500 INFO TcpOutputProc - Detected connection to xx.xx.xx.xx:9997 closed&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:50:39.168 -0500 INFO TcpOutputProc - Will close stream to current indexer xx.xx.xx.xx:9997&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:50:39.168 -0500 INFO TcpOutputProc - Closing stream for idx=xx.xx.xx.xx:9997&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:51:00.107 -0500 WARN TcpOutputProc - Cooked connection to ip=xx.xx.xx.xx:9997 timed out&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:55:39.110 -0500 WARN TcpOutputProc - Shutdown timed out for xx.xx.xx.xx:9997&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:56:09.110 -0500 WARN TcpOutputProc - Cooked connection to ip=xx.xx.xx.xx:9997 timed out&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 20:57:49.114 -0500 WARN TcpOutputProc - Connected to idx=xx.xx.xx.xx:9997. Not using ACK.&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 21:03:09.116 -0500 WARN TcpOutputProc - Raw connection to ip=xx.xx.xx.xx:9997 timed out&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 21:03:09.116 -0500 INFO TcpOutputProc - Detected connection to xx.xx.xx.xx:9997 closed&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 21:03:09.116 -0500 INFO TcpOutputProc - Will close stream to current indexer xx.xx.xx.xx:9997&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 21:03:09.116 -0500 INFO TcpOutputProc - Closing stream for idx=xx.xx.xx.xx:9997&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 21:03:29.601 -0500 WARN TcpOutputProc - Cooked connection to ip=xx.xx.xx.xx:9997 timed out&lt;BR /&gt;&lt;BR /&gt;
11-05-2013 21:04:09.117 -0500 WARN TcpOutputProc - Cooked connection to ip=xx.xx.xx.xx:9997 timed out   &lt;/P&gt;

&lt;P&gt;Here is the configuration on the forwarder:&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;outputs.conf&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;
&lt;STRONG&gt;[tcpout]&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;defaultGroup = default&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;[tcpout:default]&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;server = xx.xx.xx.xx:9997&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;[tcpout-server://xx.xx.xx.xx:9997]&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:40:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131353#M26998</guid>
      <dc:creator>john_byun</dc:creator>
      <dc:date>2013-11-06T18:40:06Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131354#M26999</link>
      <description>&lt;P&gt;My first thought is that port 9997 is blocked. You should make sure that the port is open from the indexer to the forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:54:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131354#M26999</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-11-06T18:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131355#M27000</link>
      <description>&lt;P&gt;Do you definitely have appropriate routing?  Since you have redacted your source address it impossible to know if this is relevant.  Are there firewalls intervening?  Do they have rules to allow TCP on 9997 from source to indexer?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131355#M27000</guid>
      <dc:creator>grijhwani</dc:creator>
      <dc:date>2013-11-06T18:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131356#M27001</link>
      <description>&lt;P&gt;It's not being blocked.  I can successfully telnet to port 9997 from the forwarder to the indexer.&lt;/P&gt;

&lt;P&gt;Also, if it were blocked, I would not see the error message above from the indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:58:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131356#M27001</guid>
      <dc:creator>john_byun</dc:creator>
      <dc:date>2013-11-06T18:58:54Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131357#M27002</link>
      <description>&lt;P&gt;What is the configuration on the indexer? Specifically, what is in the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; stanza that set up the &lt;CODE&gt;tcpinput&lt;/CODE&gt; on 9997?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2013 21:21:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131357#M27002</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-11-06T21:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131358#M27003</link>
      <description>&lt;P&gt;Hmm...even though it was showing in the web gui, I couldn't find it in any of the inputs.conf files.  I confirmed it was listening on 9997 using netstat.&lt;/P&gt;

&lt;P&gt;In any case, I explicitly added it to my inputs.conf from the /splunk/etc/apps/search/local folder.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;[splunktcp://9997]&lt;/STRONG&gt;&lt;BR /&gt;
&lt;STRONG&gt;connection_host = dns&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I am still not seeing any data come in.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Nov 2013 23:29:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131358#M27003</guid>
      <dc:creator>john_byun</dc:creator>
      <dc:date>2013-11-06T23:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131359#M27004</link>
      <description>&lt;P&gt;had the same problem, couldnt connect to indexer&lt;BR /&gt;
in windows for universal forwarder installation ( 5.0.4) please check the files in:&lt;BR /&gt;
path /SplunkUniversalForwarder/etc/system/local &lt;BR /&gt;
replace the  config files under  with those from:&lt;BR /&gt;
path /SplunkUniversalForwarder/etc/apps/Windows/local &lt;BR /&gt;
restart splunkforwarder:&lt;BR /&gt;
splunk restart&lt;/P&gt;

&lt;P&gt;it should get connected&lt;BR /&gt;
in splunk host i can see the forwarder has been connected and it has send logs. i had activated some advanced audit features.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2013 10:20:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131359#M27004</guid>
      <dc:creator>Akili</dc:creator>
      <dc:date>2013-12-24T10:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131360#M27005</link>
      <description>&lt;P&gt;add manually into file&lt;BR /&gt;
opt/splunk/etc/system/local/inputs.conf&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;BR /&gt;
disabled = 0&lt;/P&gt;</description>
      <pubDate>Wed, 23 Apr 2014 18:01:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131360#M27005</guid>
      <dc:creator>kuido7Xdoc</dc:creator>
      <dc:date>2014-04-23T18:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder not sending data - timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131361#M27006</link>
      <description>&lt;P&gt;Well, old question but maybe worth to comment:&lt;/P&gt;

&lt;P&gt;Remember to check you have a rule in inputs.conf somewhere.&lt;/P&gt;

&lt;P&gt;Check this with&lt;/P&gt;

&lt;P&gt;splunk btool inputs list --debug | less &lt;/P&gt;

&lt;P&gt;and search for a stanza where there is NO "disable = 1" entry!&lt;/P&gt;

&lt;P&gt;HTH,&lt;/P&gt;

&lt;P&gt;Holger&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jul 2016 15:39:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-not-sending-data-timed-out/m-p/131361#M27006</guid>
      <dc:creator>hsesterhenn_spl</dc:creator>
      <dc:date>2016-07-22T15:39:14Z</dc:date>
    </item>
  </channel>
</rss>

