Getting Data In

Splunk universal forwarder issues in windows

Sravane
Observer

Hi All - I have installed SPlunk master in Linux and universal forwarder in Windows box.

And Also opened all Ports .Currently when i do Telnet server ip 9997 ,it is showing timeout in windows box.

In Splunk logs found following warning.Cooked connectioned timeout and some certificate issues.

 

Can you please provide rootcause or solution  for this issue.

 

 

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sravane,

let me understand:

  • you have Splunk Enterprise on a Linux server (Indexer),
  • you have a Universal Forwarder on Linux,
  • you're testing connection betweem Forwarder and Indexer using Telnet from Forwarder to Indexer and you fail;

is it correct?

If this is your situation, you have to check the following items:

  • did you enabled receiving on Indexer on 9997 port?
  • did you disabled local firewall on Indexer?
  • are you sure that there isn't any Firewall between Forwarder and Indexer,
  • Are they in different network segments?

Check the above items and then try again with telnet.

Ciao.

Giuseppe

0 Karma

Sravane
Observer

Hi Ciao -Let explain question 

  • My Splunk Enterprise on a Linux server (Indexer),
  • And my Universal Forwarder on windows
  • Added 9997 port in Splunk master

And connection between Splunk enterprise and forwarder is failing. We enabled ports aswell

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sravane,

are you saying that:

  • you enabled receiving on Indexer on 9997 port [Settings -- Forwarding and Receiving -- receiving];
  • you disabled local firewall on Indexer (iptables);
  • you're sure that there isn't any Firewall between Forwarder and Indexer;
  • both the servers are in the same network segments.

Can you confirm?

If telnet from Forwarder to Indexer fails, probably one of the previous checks is wrong.

Ciao.

Giuseppe

0 Karma

Sravane
Observer

Hi -Please let me know how to disable firewall?

  • you disabled local firewall on Indexer (iptables);

ANy commands to run?

Moreover,i tried telnet ip 9997 in universal forwared server and i got following error


"Configured but inactive forwards"

Thanks,

Sravan

Thanks,

Sravan

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sravane,

it depends on the Linux version you're using, you can search it in Google.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...