Feedback
Got feedback? We want it! Submit your comments and suggestions for our community here.

Universal Forwarder will not activate

johnnyp74
Observer

I have installed and configured my Universal forwarder, however while it starts it remains inactive:

Active forwards:
None

Configured but inactive forwards:
10.###.##.##:9997

I have validated that I am using the correct ip address, and that I can ping the indexer from the forwarder,  and that port 9997 is not blocked.  So at this point Im just not sure how to resolve this?  Any assistance would be appreciated.

Thanks!

0 Karma

zksvc
Contributor

Have you made sure port 9997 is enabled on Receive Data?

You can go to "Settings -> Forwarding And Receiving -> Receive data -> +Add new"

zksvc_1-1745829865488.png

 

 

0 Karma

khj
Explorer

1. Make sure the UF is operating normally.
$SPLUNK_HOME/bin/splunk status
There should be no message other than the phrase is running.

2. Make sure that the log path you set in inputs.conf has a log

3. Make sure the inputs.conf settings are set correctly
If you set the index, the index must be created in the indexer.

4. Check the UI of the indexer to see if the data is in.
This method is more intuitive than checking with the inputs status of the cli.

5. Search index=_internal and search UF's IP to see if there are any problems

Karma if this has helped!

SanjayReddy
SplunkTrust
SplunkTrust

Hi @johnnyp74 

have you restarted splunk service after updating outputs.conf 

and as you mentioned you did ping to check connectivity 

however have you did telent on port 9997 to indexer?

telnet <indexerip> 9997 

in Splunkd.log have you seen any error messages, certainly splunkd.log messages help  to troubleshoot further   




0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...