- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk universal forwarder issues in windows
Hi All - I have installed SPlunk master in Linux and universal forwarder in Windows box.
And Also opened all Ports .Currently when i do Telnet server ip 9997 ,it is showing timeout in windows box.
In Splunk logs found following warning.Cooked connectioned timeout and some certificate issues.
Can you please provide rootcause or solution for this issue.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Sravane,
let me understand:
- you have Splunk Enterprise on a Linux server (Indexer),
- you have a Universal Forwarder on Linux,
- you're testing connection betweem Forwarder and Indexer using Telnet from Forwarder to Indexer and you fail;
is it correct?
If this is your situation, you have to check the following items:
- did you enabled receiving on Indexer on 9997 port?
- did you disabled local firewall on Indexer?
- are you sure that there isn't any Firewall between Forwarder and Indexer,
- Are they in different network segments?
Check the above items and then try again with telnet.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ciao -Let explain question
- My Splunk Enterprise on a Linux server (Indexer),
- And my Universal Forwarder on windows
- Added 9997 port in Splunk master
And connection between Splunk enterprise and forwarder is failing. We enabled ports aswell
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @Sravane,
are you saying that:
- you enabled receiving on Indexer on 9997 port [Settings -- Forwarding and Receiving -- receiving];
- you disabled local firewall on Indexer (iptables);
- you're sure that there isn't any Firewall between Forwarder and Indexer;
- both the servers are in the same network segments.
Can you confirm?
If telnet from Forwarder to Indexer fails, probably one of the previous checks is wrong.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi -Please let me know how to disable firewall?
- you disabled local firewall on Indexer (iptables);
ANy commands to run?
Moreover,i tried telnet ip 9997 in universal forwared server and i got following error
"Configured but inactive forwards"
Thanks,
Sravan
Thanks,
Sravan
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


