Hi,
Thanks for the answer. I have setup receiver and I have enabled this.
Now my node tries to setup a TCP connection by sending SYN. Now the splunk server sends SYN ACK and my node sends ACK to this.
Then immediately, the splunk server sends FIN -ACK to this.
Pls help me in solving this.
Well, does your forwarder have any data to forward?
Yes. After establishing the TCP connection, it will have the events which it will forward.
Sorry if I missed it, but then what's the problem?
The TCP connection is getting refused. FIN is being sent anter SYN ACK 😞
The way I see it, it is not refused - there is simply no data exchanged before the connection is closed, see this diagram. Why that is I have no idea, sorry - but the connection is there and it works as it should.
You need to enable receiving on the windows instance, which can be done via conf files, the web interface or the command line interface. On the linux instance you'll have to use either conf files or the command line to forward data to the windows instance; see here on how to do that.