Getting Data In

My Splunk Enterprise don't accept telnet or tcp (my computer) from different networks

Cyner__
Loves-to-Learn Everything

Hi. I am new to splunk. I have configured everything. I am trying to solve this issue for 2 days.

I have universal forwerder on the ubuntu server with different network. I have downloaded splunk enterprise to my windows 10 computer.

My port 9997 is enabled. Firewall is disabled. Even with zyxel interface i bypassed the port 9997.

My splunk is listening on port 9997.

The thing is with telnet from any other source to my computer (i tried with both my mobile internet and UF client) is still getting denied.

How should i proceed to make it work. Im stuck so bad

Thanks for your helps

this is the mobile internet test with Test-NetConnections to my pc (splunk server i guess)

ComputerName : x.x.x.x <desired.connection>

RemoteAddress : x.x.x.x <desired connection>
RemotePort : 9997
InterfaceAlias : Wi-Fi
SourceAddress : X.x.x.x <my ip>
PingSucceeded : False
PingReplyDetails (RTT) : 0 ms
TcpTestSucceeded : False

 

Labels (2)
0 Karma

tscroggins
Influencer

Hi @Cyner__,

If both devices are connected to your Zyxel access point / router using WiFi, make sure layer-2 isolation is correctly configured for the devices to communicate. You should be able to find instructions for configuring isolation white lists in your Zyxel documentation.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @Cyner__ 

from the UF, are you able to ping the indexer?

from the UF to indexer, is telnet working fine?

telnet index:9997 .. is it working fine or not.. 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...