Getting Data In

Need to establish a TCP connection with my HOSTS

arun85_123
New Member

I have installed SPLUNK in my windows server. I need to establish a TCP connection with another LINUX host which will be forwarding the events to this splunk server.
Help me on this.

Tags (2)
0 Karma

arun85_123
New Member

Hi,

Thanks for the answer. I have setup receiver and I have enabled this.
Now my node tries to setup a TCP connection by sending SYN. Now the splunk server sends SYN ACK and my node sends ACK to this.
Then immediately, the splunk server sends FIN -ACK to this.

Pls help me in solving this.

0 Karma

jeffland
SplunkTrust
SplunkTrust

Well, does your forwarder have any data to forward?

0 Karma

arun85_123
New Member

Yes. After establishing the TCP connection, it will have the events which it will forward.

0 Karma

jeffland
SplunkTrust
SplunkTrust

Sorry if I missed it, but then what's the problem?

0 Karma

arun85_123
New Member

The TCP connection is getting refused. FIN is being sent anter SYN ACK 😞

0 Karma

jeffland
SplunkTrust
SplunkTrust

The way I see it, it is not refused - there is simply no data exchanged before the connection is closed, see this diagram. Why that is I have no idea, sorry - but the connection is there and it works as it should.

0 Karma

jeffland
SplunkTrust
SplunkTrust

You need to enable receiving on the windows instance, which can be done via conf files, the web interface or the command line interface. On the linux instance you'll have to use either conf files or the command line to forward data to the windows instance; see here on how to do that.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...