Getting Data In

How to troubleshoot why my universal forwarder is showing Splunk Cloud hosts as inactive?

pkurt
Path Finder

Hello,

I have installed and used the Splunk universal forwarder to successfully forward my data to my local Splunk Enterprise server. I followed the instructions http://answers.splunk.com/answers/50082/how-do-i-configure-a-splunk-forwarder-on-linux.html. I then followed the same instructions for two different cloud hosts, but neither worked. Both listed the host as inactive. I cannot even ping either of the hosts. I have seen some people say that a firewall could block the forwarder. Is it possible that this is the cause? Both Splunk cloud hosts are configured to receive on port 9997. If it is a firewall problem, how can I fix it for the Splunk cloud trial version?

Here is the problem:
splunk list forward-server
Active forwards:
Pelins-Macbook-Pro.local:9997
Configured but inactive forwards:
prd-p-26fhqv8slwd9.cloud.splunk.com:9997
prd-p-tvrqpx4kg23s.cloud.splunk.com:9997

I would greatly appreciate any advice or help!

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

The SplunkCloud instance provides an app package that contains the outputs and the certificates. It will work if you install it on a fresh splunk forwarder.
However if the forwarder has already be configured to forward, it may be a conflict problem between several outputs.conf tcpout definitions.

You need to use btool list outputs --debug and find the conflict, usually this is the defaultgroup that is pointing to only one group, and you need to edit it to list the 2 groups.
example :
[tcpout]
defaultGroup= cloudgroup, localindexergroup

see similar post http://answers.splunk.com/answers/290948/can-i-forward-to-2-splunkcloud-deployments-at-a-ti.html

View solution in original post

yannK
Splunk Employee
Splunk Employee

The SplunkCloud instance provides an app package that contains the outputs and the certificates. It will work if you install it on a fresh splunk forwarder.
However if the forwarder has already be configured to forward, it may be a conflict problem between several outputs.conf tcpout definitions.

You need to use btool list outputs --debug and find the conflict, usually this is the defaultgroup that is pointing to only one group, and you need to edit it to list the 2 groups.
example :
[tcpout]
defaultGroup= cloudgroup, localindexergroup

see similar post http://answers.splunk.com/answers/290948/can-i-forward-to-2-splunkcloud-deployments-at-a-ti.html

pkurt
Path Finder

Thank you very much for your answer!
Indeed, it worked easily after I refreshed my universal forwarder.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...