Getting Data In

SplunkUniversalForwarder: Cooked connection to ip=192.168.0.115:9997 timed out

mathdewulf
New Member

I installed Splunk on my laptop and wanted to receive the logs from 2 other desktops.
So on these desktops I installed the SplunkUniversalForwarder to send everything to my laptop.
However, on both desktops I checked the log files and every minut the following event is generated:

06-07-2013 17:43:12.091 +0200 WARN  TcpOutputProc - Cooked connection to ip=192.168.0.115:9997 timed out

On my laptop, I configured receiving so don't know how to troubleshoot this?
The desktops and my laptop are in same network.

0 Karma

dwaddle
SplunkTrust
SplunkTrust

A desktop firewall, perhaps? The outbound connection could be being blocked at the source, or the inbound connection being blocked at your laptop.

If any of the hosts involved are running a firewall product, you should make sure the necessary rules/exceptions are properly configured and check the firewall logs to see if there is any explicit message about things being blocked.

bmacias84
Champion

It a little hard without your inputs and outputs conf files. Could you post a scrubbed verion? Also turn TcpOutputProc channel to DEBUG. Are you using a wireless network?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...