<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I troubleshoot Splunk Universal Forwarder communication issues? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209911#M41352</link>
    <description>&lt;P&gt;It look fine in my splunk log and i got this message:&lt;BR /&gt;
06-16-2016 10:13:26.851 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IPAddress&lt;BR /&gt;
This should be correct right?&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2016 02:16:30 GMT</pubDate>
    <dc:creator>qygoh</dc:creator>
    <dc:date>2016-06-16T02:16:30Z</dc:date>
    <item>
      <title>How do I troubleshoot Splunk Universal Forwarder communication issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209906#M41347</link>
      <description>&lt;P&gt;I'm facing 1 issue when try to install a Splunk universal forwarder in one of my job sites. Every time when I change its connection to 127.0.0.1 51112, it will fail after 3 minutes of waiting and reset the connection again. Therefore, data at my client site can't send to my server. Anyone of you encounter this issue before? Do you mind sharing your solution so I can resolve it?I able to telnet it and also splunk list forward server &amp;amp; splunk show deploy-poll is working well. Thank you very much. &lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 08:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209906#M41347</guid>
      <dc:creator>qygoh</dc:creator>
      <dc:date>2016-06-14T08:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I troubleshoot Splunk Universal Forwarder communication issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209907#M41348</link>
      <description>&lt;P&gt;What do you mean by "change its connection to 127.0.0.1 51112"?  Why do you need to do that?  From the little I see in your screenshot your configuration looks fine*.&lt;/P&gt;

&lt;P&gt;You can check c:\program files\splunkforwarder\var\log\splunk\splunkd.log for errors, that might help point you in the right direction.&lt;/P&gt;

&lt;P&gt;*Except having your system forward to the same place as your Deployment Server, but that shouldn't be an actual problem.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 12:02:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209907#M41348</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2016-06-14T12:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I troubleshoot Splunk Universal Forwarder communication issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209908#M41349</link>
      <description>&lt;P&gt;What does your Splunk infrastructure look like? Is your Deployment Server also your indexer?  &lt;/P&gt;

&lt;P&gt;Are you receiving any data on your indexer? &lt;/P&gt;

&lt;P&gt;Do you have port 9997 open between your Universal Forwarder and Indexer?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2016 12:38:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209908#M41349</guid>
      <dc:creator>ryanoconnor</dc:creator>
      <dc:date>2016-06-14T12:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: How do I troubleshoot Splunk Universal Forwarder communication issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209909#M41350</link>
      <description>&lt;P&gt;127.0.0.1 51112 is the same as as point to localhost. I use Kepware 5.20 for extract all the data from my device and send to Splunk server. I will try to check the Splunk log see got any hints or not.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 05:21:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209909#M41350</guid>
      <dc:creator>qygoh</dc:creator>
      <dc:date>2016-06-15T05:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: How do I troubleshoot Splunk Universal Forwarder communication issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209910#M41351</link>
      <description>&lt;P&gt;Hi, yup~ i able to telnet port my port which mean the port is open already. I able to received data from my indexer before i install universal forwarder. But after i install Universal forwarder it can't working. Any details information i should provide to you? &lt;/P&gt;</description>
      <pubDate>Wed, 15 Jun 2016 05:26:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209910#M41351</guid>
      <dc:creator>qygoh</dc:creator>
      <dc:date>2016-06-15T05:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I troubleshoot Splunk Universal Forwarder communication issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209911#M41352</link>
      <description>&lt;P&gt;It look fine in my splunk log and i got this message:&lt;BR /&gt;
06-16-2016 10:13:26.851 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IPAddress&lt;BR /&gt;
This should be correct right?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2016 02:16:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209911#M41352</guid>
      <dc:creator>qygoh</dc:creator>
      <dc:date>2016-06-16T02:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: How do I troubleshoot Splunk Universal Forwarder communication issues?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209912#M41353</link>
      <description>&lt;P&gt;Resolved as port 51112 is intermittently controlled by another app. Shifted to another port number.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 07:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-troubleshoot-Splunk-Universal-Forwarder-communication/m-p/209912#M41353</guid>
      <dc:creator>Stevelim</dc:creator>
      <dc:date>2016-06-21T07:18:50Z</dc:date>
    </item>
  </channel>
</rss>

