I have installed Uf in one linux and splunk instance in another linux/windows. While trying to configure , uf is not forwarding data to linux/windows splunk,ping is working fine.
Could you please help me on this.
Hi!
1) Try to restart frowarder
2) Check index = _internal
for forwarder logs existence
If it is not working, please provide us full your outputs.conf config
I would also check the _internal on the Splunk Indexer to see if you can see the UF host connecting to the Indexer. Is the host anywhere in the logs? It could be that the server is connecting but your app has an issue with it's input.conf
i have configured outputs.conf (ip:9997) in linux universal forwarder and at splunk instances configured receiver as 9997. but still not working.
i have stop firewall with sudo ufw disable and tried. but still not working
Have you validated that your Splunk indexer is listening on port 9997 and that your UF is configured in the outputs.conf to send to your indexer over port 9997? I would also validate that you have port 9997 open in your firewall as well. You can validate this with telnet.
i have configured outputs.conf (ip:9997) in linux universal forwarder and at splunk instances configured receiver as 9997. but still not working.
i have stop firewall with sudo ufw disable and tried. but still not working
its working fine with heavy forwarder but not with universal forwarder
Can you telnet over port 9997? Also have you checked the physical firewall to ensure that the ports are open?