Getting Data In

Configured but inactive forwards

julian0125
Explorer

Hello Splunkers!

i'm in doubt, i have installed UF on windows server but when i list forward-server it says that there are no active fordware but is configurated, on port 9997 and also de deploy with 8088. What issue do you think it is? is there a way to active the forwarder?

Thanks

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi julian0125,
did you checked if the connection ports are open? you can check them using telnet.
then, you can check in forwarder's logs ($SPLUNK_HOME/var/log/splunk/) if the connection is established.
At least check if the forwarder is active, you can check the process (ps -eafd) searching for splunkd process.
If you find that the process is active and ports are open, check if the servername is correct ($SPLUNK_HOME/etc/system/local/server.conf e $SPLUNK_HOME/etc/system/local/inputs.conf).

You can see at https://docs.splunk.com/Documentation/Forwarder/7.3.0/Forwarder/Troubleshoottheuniversalforwarder or https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Receiverconnection

Bye.
Giuseppe

0 Karma

natalienguyen
Explorer

Did you restart your splunkforwarder service after the configuration?

0 Karma

ddrillic
Ultra Champion

Yup - you need to start it, probably as a service.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...