Getting Data In

Splunk universal forwarder issues in windows

Sravane
Observer

Hi All - I have installed SPlunk master in Linux and universal forwarder in Windows box.

And Also opened all Ports .Currently when i do Telnet server ip 9997 ,it is showing timeout in windows box.

In Splunk logs found following warning.Cooked connectioned timeout and some certificate issues.

 

Can you please provide rootcause or solution  for this issue.

 

 

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sravane,

let me understand:

  • you have Splunk Enterprise on a Linux server (Indexer),
  • you have a Universal Forwarder on Linux,
  • you're testing connection betweem Forwarder and Indexer using Telnet from Forwarder to Indexer and you fail;

is it correct?

If this is your situation, you have to check the following items:

  • did you enabled receiving on Indexer on 9997 port?
  • did you disabled local firewall on Indexer?
  • are you sure that there isn't any Firewall between Forwarder and Indexer,
  • Are they in different network segments?

Check the above items and then try again with telnet.

Ciao.

Giuseppe

0 Karma

Sravane
Observer

Hi Ciao -Let explain question 

  • My Splunk Enterprise on a Linux server (Indexer),
  • And my Universal Forwarder on windows
  • Added 9997 port in Splunk master

And connection between Splunk enterprise and forwarder is failing. We enabled ports aswell

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sravane,

are you saying that:

  • you enabled receiving on Indexer on 9997 port [Settings -- Forwarding and Receiving -- receiving];
  • you disabled local firewall on Indexer (iptables);
  • you're sure that there isn't any Firewall between Forwarder and Indexer;
  • both the servers are in the same network segments.

Can you confirm?

If telnet from Forwarder to Indexer fails, probably one of the previous checks is wrong.

Ciao.

Giuseppe

0 Karma

Sravane
Observer

Hi -Please let me know how to disable firewall?

  • you disabled local firewall on Indexer (iptables);

ANy commands to run?

Moreover,i tried telnet ip 9997 in universal forwared server and i got following error


"Configured but inactive forwards"

Thanks,

Sravan

Thanks,

Sravan

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @Sravane,

it depends on the Linux version you're using, you can search it in Google.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

(re)Introducing the Splunk Community Champions + 2026 – 2027 Splunk MVPs ...

This program exists as a channel to empower and recognize Splunk advocates and help supercharge initiatives to ...

Pro Tips for .conf26: How to Prep Like a Splunk Veteran

There’s no shortage of incredible content lined up for .conf26 in Denver, from deep-dive technical sessions ...