Getting Data In

Configured but inactive forwards

julian0125
Explorer

Hello Splunkers!

i'm in doubt, i have installed UF on windows server but when i list forward-server it says that there are no active fordware but is configurated, on port 9997 and also de deploy with 8088. What issue do you think it is? is there a way to active the forwarder?

Thanks

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi julian0125,
did you checked if the connection ports are open? you can check them using telnet.
then, you can check in forwarder's logs ($SPLUNK_HOME/var/log/splunk/) if the connection is established.
At least check if the forwarder is active, you can check the process (ps -eafd) searching for splunkd process.
If you find that the process is active and ports are open, check if the servername is correct ($SPLUNK_HOME/etc/system/local/server.conf e $SPLUNK_HOME/etc/system/local/inputs.conf).

You can see at https://docs.splunk.com/Documentation/Forwarder/7.3.0/Forwarder/Troubleshoottheuniversalforwarder or https://docs.splunk.com/Documentation/Splunk/7.3.0/Forwarding/Receiverconnection

Bye.
Giuseppe

0 Karma

natalienguyen
Explorer

Did you restart your splunkforwarder service after the configuration?

0 Karma

ddrillic
Ultra Champion

Yup - you need to start it, probably as a service.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...