Getting Data In

How to configure a Splunk Universal forwarder on a remote system?


I've already installed the Splunk Universal Forwarder in my remote PC. I gave the Indexer the IP to receive the data from the remote machine and also configured the port in my indexer as 9997 default, which I gave in my forwarder. I haven't received any data from that host. What's the issue and where do I need to make configuration changes?

Please help me out.

Did you open the firewall ports between the indexer and UF?

You can use telnet to test.

