<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk forwarder not detecting in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741772#M240696</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243238"&gt;@okumar1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what about telnet test?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Fri, 14 Mar 2025 06:55:54 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2025-03-14T06:55:54Z</dc:date>
    <item>
      <title>splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741673#M240662</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello everyone,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have set up my Splunk server[with receiving port 9997 is enabled] and Splunk forwarder to monitor my UF logs.&amp;nbsp; Please suggest what i am missing here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but i am getting below when i do - ./splunk list forward-server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;o/p:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Active forwards:&lt;BR /&gt;&lt;STRONG&gt;None&lt;/STRONG&gt;&lt;BR /&gt;Configured but inactive forwards:&lt;BR /&gt;52.66.100.58:9997&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i have done below steps:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;my UF:&amp;nbsp; ./splunk add forward-server 52.66.100.58:9997&lt;/P&gt;&lt;P&gt;outputs.conf&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup = default-autolb-group&lt;/P&gt;&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;disabled = false&lt;BR /&gt;server = 52.66.100.58:9997&lt;/P&gt;&lt;P&gt;[tcpout-server://52.66.100.58:9997]&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="okumar1_0-1741856405697.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38163i790779262F25B935/image-size/medium?v=v2&amp;amp;px=400" role="button" title="okumar1_0-1741856405697.png" alt="okumar1_0-1741856405697.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="okumar1_1-1741856658254.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38164i790AEEBE6B9E329D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="okumar1_1-1741856658254.png" alt="okumar1_1-1741856658254.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 09:07:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741673#M240662</guid>
      <dc:creator>okumar1</dc:creator>
      <dc:date>2025-03-13T09:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741679#M240665</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243238"&gt;@okumar1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;at first, did you checked if the connection (firewall route) is open between UF and IDX on the 9997 port?&lt;/P&gt;&lt;P&gt;you can check this on UF using telnet.&lt;/P&gt;&lt;P&gt;Then, is the 9997 port open on the IDX local firewall?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 09:54:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741679#M240665</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-03-13T09:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741681#M240666</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243238"&gt;@okumar1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see you have put a screenshot of the rule that allows inbound traffic to your server, but is your UF server also configured with outbound connectivity on port 9997?&lt;/P&gt;&lt;P&gt;If you are using linux with netcat installed then this might work well to test:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;nc -vz -w1 yourServerIP 9997

you can also check with portquiz.net
nc -vz -w1 portquiz.net 9997&lt;/LI-CODE&gt;&lt;P&gt;The portquiz.net test relies on you being able to reach the internet from your server.&lt;/P&gt;&lt;P&gt;Let us know how you get on and we can investigate further.&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 10:04:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741681#M240666</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-13T10:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741765#M240689</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;as per your comment, yes my UF has outbound rules set on port 9997, still not working. Please suggest&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="okumar1_0-1741931609585.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38190i94D73A6F259F85D5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="okumar1_0-1741931609585.png" alt="okumar1_0-1741931609585.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 05:54:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741765#M240689</guid>
      <dc:creator>okumar1</dc:creator>
      <dc:date>2025-03-14T05:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741771#M240695</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243238"&gt;@okumar1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were you able to check the netcat/nc commands?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any other logs around mentioning tcpOutput in your UF?&lt;/P&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 06:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741771#M240695</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-14T06:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741772#M240696</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243238"&gt;@okumar1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what about telnet test?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 06:55:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741772#M240696</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-03-14T06:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741774#M240697</link>
      <description>&lt;P&gt;here is the output&lt;/P&gt;&lt;P&gt;[root@ip-172-31-13-139 log]# nc -vz -w1 13.233.165.44 9997&lt;BR /&gt;Ncat: Version 7.50 ( &lt;A href="https://nmap.org/ncat" target="_blank"&gt;https://nmap.org/ncat&lt;/A&gt; )&lt;BR /&gt;Ncat: Connection refused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no&amp;nbsp; my outputs.conf is below:&lt;/P&gt;&lt;P&gt;[tcpout]&lt;BR /&gt;defaultGroup = default-autolb-group&lt;/P&gt;&lt;P&gt;[tcpout:default-autolb-group]&lt;BR /&gt;server = 13.233.165.44:9997&lt;/P&gt;&lt;P&gt;and when i debug splunkd.log&lt;/P&gt;&lt;P&gt;The TCP output processor has paused the data flow. Forwarding to host_dest=13.233.165.44 inside output group default-autolb-group from host_src=ip-172-31-13-139.ap-south-1.compute.internal has been blocked for blocked_seconds=100. This can stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data&lt;/P&gt;&lt;P&gt;please suggest&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 07:22:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741774#M240697</guid>
      <dc:creator>okumar1</dc:creator>
      <dc:date>2025-03-14T07:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741776#M240698</link>
      <description>&lt;P&gt;hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;here is the telnet test&lt;/P&gt;&lt;P&gt;telnet: connect to address 13.233.165.44: Connection refused&lt;/P&gt;&lt;P&gt;and splund.log&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="okumar1_0-1741937052195.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/38191iB2F3BB3C57D0A40C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="okumar1_0-1741937052195.png" alt="okumar1_0-1741937052195.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;please suggest.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 07:25:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741776#M240698</guid>
      <dc:creator>okumar1</dc:creator>
      <dc:date>2025-03-14T07:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: splunk forwarder not detecting</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741778#M240700</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243238"&gt;@okumar1&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;this means that there's something in the middle between UD and IDX that block the connection.&lt;/P&gt;&lt;P&gt;probably an intermediate firewall or a local firewall on the IDX.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 07:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-forwarder-not-detecting/m-p/741778#M240700</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-03-14T07:49:30Z</dc:date>
    </item>
  </channel>
</rss>

