what are the possible connections to be checked after installing Universal forwarder to extract logs in to Splunk Indexer
Telnet from the forwarder to you indexers
telnet hostname 9997
If your forwarder is behind the firewall you won't be able to connect.
check for "err_connected " handshake exception logs in
/Splunk_home/var/logs/splunkd.log
Can you Tell me more clear please I am new to Splunk I didn't get your point