- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
UF not connecting with Splunk Enterprise (Cooked connection timed out)
HankinAlex
Explorer
12-19-2023
01:30 PM
Hello, I have tried numerous configurations to get my Splunk Universal Forwarder to connect to my Splunk Enterprise instance with no luck. I am trying to forward data to my indexer located on port 3389 with the only info in the logs reading
WARN AutoLoadBalancedConnectionStrategy [136236 TcpOutEloop] - Cooked connection to ip=XX.XX.XX.XX:3389 timed out
I have checked telnet with that port in both directions and the connection is successful. Any advice would be appreciated
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

gcusello

SplunkTrust
12-19-2023
11:42 PM
Hi @HankinAlex,
at firt the port you are usig is unusual, the default port for UF to IDX is 9997.
Anyway:
- did you configured your IDX to receive logs from UFs on this port [Settings > Forwarding and Receiving > Receiving]?
- did you configured your UF to send logs to the IDX editing outputs.conf file?
You can find detailed instructions at https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/Usingforwardingagents
Ciao.
Giuseppe
