Getting Data In

Free trial forwarder problems

amir_ma
Loves-to-Learn

Hi,

I am using a free trial of splunk and I am facing two mean problem when using forwarders (heavy and universal).

Thanks. 

 

splunk_2.png

Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @amir_ma,

let me understand:

  • you have an Indexers (amir-X55LDB) with a free license,
  • you have an Heavy Forwarder that gives two messages you shared,
  • you have an Universal Forwarder that gives the first message you shared;

is it correct?

The first message says the the Forwarders don't reach the Indexer, you can test the connection using telnet from the Forwarders:

telnet <ip_indexer> 9997

maybe it's closed the firewall on  network or on Indexer, or maybe indexer is in a different network than Forwarders and it its'n reachable; anyway check connections.

I didn't see the second message, but probably is related to the free license, anyway, if you  solve the first problem I think that also the second will be solved.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...