<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk universal forwarder issues in windows in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535352#M89787</link>
    <description>&lt;P&gt;Hi Ciao -Let explain question&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;My Splunk Enterprise on a Linux server (Indexer),&lt;/LI&gt;&lt;LI&gt;And my Universal Forwarder on windows&lt;/LI&gt;&lt;LI&gt;Added 9997 port in Splunk master&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And connection between Splunk enterprise and forwarder is failing. We enabled ports aswell&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jan 2021 14:42:43 GMT</pubDate>
    <dc:creator>Sravane</dc:creator>
    <dc:date>2021-01-11T14:42:43Z</dc:date>
    <item>
      <title>Splunk universal forwarder issues in windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535334#M89783</link>
      <description>&lt;P&gt;Hi All - I have installed SPlunk master in Linux and universal forwarder in Windows box.&lt;/P&gt;&lt;P&gt;And Also opened all Ports .Currently when i do Telnet server ip 9997 ,it is showing timeout in windows box.&lt;/P&gt;&lt;P&gt;In Splunk logs found following warning.Cooked connectioned timeout and some certificate issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please provide rootcause or solution&amp;nbsp; for this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 11:23:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535334#M89783</guid>
      <dc:creator>Sravane</dc:creator>
      <dc:date>2021-01-11T11:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder issues in windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535338#M89785</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230363"&gt;@Sravane&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you have Splunk Enterprise on a Linux server (Indexer),&lt;/LI&gt;&lt;LI&gt;you have a Universal Forwarder on Linux,&lt;/LI&gt;&lt;LI&gt;you're testing connection betweem Forwarder and Indexer using Telnet from Forwarder to Indexer and you fail;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;is it correct?&lt;/P&gt;&lt;P&gt;If this is your situation, you have to check the following items:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;did you enabled receiving on Indexer on 9997 port?&lt;/LI&gt;&lt;LI&gt;did you disabled local firewall on Indexer?&lt;/LI&gt;&lt;LI&gt;are you sure that there isn't any Firewall between Forwarder and Indexer,&lt;/LI&gt;&lt;LI&gt;Are they in different network segments?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Check the above items and then try again with telnet.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 12:03:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535338#M89785</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-11T12:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder issues in windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535352#M89787</link>
      <description>&lt;P&gt;Hi Ciao -Let explain question&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;My Splunk Enterprise on a Linux server (Indexer),&lt;/LI&gt;&lt;LI&gt;And my Universal Forwarder on windows&lt;/LI&gt;&lt;LI&gt;Added 9997 port in Splunk master&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;And connection between Splunk enterprise and forwarder is failing. We enabled ports aswell&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 14:42:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535352#M89787</guid>
      <dc:creator>Sravane</dc:creator>
      <dc:date>2021-01-11T14:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder issues in windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535357#M89788</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230363"&gt;@Sravane&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;are you saying that:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you enabled receiving on Indexer on 9997 port [Settings -- Forwarding and Receiving -- receiving];&lt;/LI&gt;&lt;LI&gt;you disabled local firewall on Indexer (iptables);&lt;/LI&gt;&lt;LI&gt;you're sure that there isn't any Firewall between Forwarder and Indexer;&lt;/LI&gt;&lt;LI&gt;both the servers are in the same network segments.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Can you confirm?&lt;/P&gt;&lt;P&gt;If telnet from Forwarder to Indexer fails, probably one of the previous checks is wrong.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 15:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535357#M89788</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-11T15:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder issues in windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535359#M89790</link>
      <description>&lt;P&gt;Hi -Please let me know how to disable firewall?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;you disabled local firewall on Indexer (iptables);&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;ANy commands to run?&lt;/P&gt;&lt;P&gt;Moreover,i tried telnet ip 9997 in universal forwared server and i got following error&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;"Configured but inactive forwards"&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sravan&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sravan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 15:26:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535359#M89790</guid>
      <dc:creator>Sravane</dc:creator>
      <dc:date>2021-01-11T15:26:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk universal forwarder issues in windows</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535362#M89791</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230363"&gt;@Sravane&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;it depends on the Linux version you're using, you can search it in Google.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 15:33:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-universal-forwarder-issues-in-windows/m-p/535362#M89791</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-01-11T15:33:11Z</dc:date>
    </item>
  </channel>
</rss>

