Getting Data In

SplunkUniversalForwarder: Cooked connection to ip=192.168.0.115:9997 timed out

mathdewulf
New Member

I installed Splunk on my laptop and wanted to receive the logs from 2 other desktops.
So on these desktops I installed the SplunkUniversalForwarder to send everything to my laptop.
However, on both desktops I checked the log files and every minut the following event is generated:

06-07-2013 17:43:12.091 +0200 WARN  TcpOutputProc - Cooked connection to ip=192.168.0.115:9997 timed out

On my laptop, I configured receiving so don't know how to troubleshoot this?
The desktops and my laptop are in same network.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

A desktop firewall, perhaps? The outbound connection could be being blocked at the source, or the inbound connection being blocked at your laptop.

If any of the hosts involved are running a firewall product, you should make sure the necessary rules/exceptions are properly configured and check the firewall logs to see if there is any explicit message about things being blocked.

bmacias84
Champion

It a little hard without your inputs and outputs conf files. Could you post a scrubbed verion? Also turn TcpOutputProc channel to DEBUG. Are you using a wireless network?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...