Getting Data In
Highlighted

Universal forwarder not forwarding to other linux/windows

New Member

I have installed Uf in one linux and splunk instance in another linux/windows. While trying to configure , uf is not forwarding data to linux/windows splunk,ping is working fine.

Could you please help me on this.

0 Karma
Highlighted

Re: Universal forwarder not forwarding to other linux/windows

Path Finder

Have you validated that your Splunk indexer is listening on port 9997 and that your UF is configured in the outputs.conf to send to your indexer over port 9997? I would also validate that you have port 9997 open in your firewall as well. You can validate this with telnet.

0 Karma
Highlighted

Re: Universal forwarder not forwarding to other linux/windows

New Member

i have configured outputs.conf (ip:9997) in linux universal forwarder and at splunk instances configured receiver as 9997. but still not working.
i have stop firewall with sudo ufw disable and tried. but still not working

0 Karma
Highlighted

Re: Universal forwarder not forwarding to other linux/windows

Path Finder

Can you telnet over port 9997? Also have you checked the physical firewall to ensure that the ports are open?

0 Karma
Highlighted

Re: Universal forwarder not forwarding to other linux/windows

New Member

its working fine with heavy forwarder but not with universal forwarder

0 Karma
Highlighted

Re: Universal forwarder not forwarding to other linux/windows

New Member

i have configured outputs.conf (ip:9997) in linux universal forwarder and at splunk instances configured receiver as 9997. but still not working.
i have stop firewall with sudo ufw disable and tried. but still not working

0 Karma
Highlighted

Re: Universal forwarder not forwarding to other linux/windows

Explorer

Hi!
1) Try to restart frowarder
2) Check index = _internal for forwarder logs existence

If it is not working, please provide us full your outputs.conf config

0 Karma
Highlighted

Re: Universal forwarder not forwarding to other linux/windows

Path Finder

I would also check the _internal on the Splunk Indexer to see if you can see the UF host connecting to the Indexer. Is the host anywhere in the logs? It could be that the server is connecting but your app has an issue with it's input.conf

0 Karma