Deployment Architecture

UF not connecting with Splunk Enterprise (Cooked connection timed out)

HankinAlex
Explorer

Hello, I have tried numerous configurations to get my Splunk Universal Forwarder to connect to my Splunk Enterprise instance with no luck. I am trying to forward data to my indexer located on port 3389 with the only info in the logs reading

WARN AutoLoadBalancedConnectionStrategy [136236 TcpOutEloop] - Cooked connection to ip=XX.XX.XX.XX:3389 timed out

I have checked telnet with that port in both directions and the connection is successful. Any advice would be appreciated

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @HankinAlex,

at firt the port you are usig is unusual, the default port for UF to IDX is 9997.

Anyway:

  • did you configured your IDX to receive logs from UFs on this port [Settings > Forwarding and Receiving > Receiving]?
  • did you configured your UF to send logs to the IDX editing outputs.conf file?

You can find detailed instructions at https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/Usingforwardingagents

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...