Deployment Architecture

UF not connecting with Splunk Enterprise (Cooked connection timed out)

HankinAlex
Explorer

Hello, I have tried numerous configurations to get my Splunk Universal Forwarder to connect to my Splunk Enterprise instance with no luck. I am trying to forward data to my indexer located on port 3389 with the only info in the logs reading

WARN AutoLoadBalancedConnectionStrategy [136236 TcpOutEloop] - Cooked connection to ip=XX.XX.XX.XX:3389 timed out

I have checked telnet with that port in both directions and the connection is successful. Any advice would be appreciated

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @HankinAlex,

at firt the port you are usig is unusual, the default port for UF to IDX is 9997.

Anyway:

  • did you configured your IDX to receive logs from UFs on this port [Settings > Forwarding and Receiving > Receiving]?
  • did you configured your UF to send logs to the IDX editing outputs.conf file?

You can find detailed instructions at https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/Usingforwardingagents

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...