Deployment Architecture

UF not connecting with Splunk Enterprise (Cooked connection timed out)

HankinAlex
Explorer

Hello, I have tried numerous configurations to get my Splunk Universal Forwarder to connect to my Splunk Enterprise instance with no luck. I am trying to forward data to my indexer located on port 3389 with the only info in the logs reading

WARN AutoLoadBalancedConnectionStrategy [136236 TcpOutEloop] - Cooked connection to ip=XX.XX.XX.XX:3389 timed out

I have checked telnet with that port in both directions and the connection is successful. Any advice would be appreciated

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @HankinAlex,

at firt the port you are usig is unusual, the default port for UF to IDX is 9997.

Anyway:

  • did you configured your IDX to receive logs from UFs on this port [Settings > Forwarding and Receiving > Receiving]?
  • did you configured your UF to send logs to the IDX editing outputs.conf file?

You can find detailed instructions at https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/Usingforwardingagents

Ciao.

Giuseppe

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...