Getting Data In

Why is universal forwarder phonehome not interpreted by deployment server?

mvbmic
Loves-to-Learn

I have been monitoring a few Windows hosts with Splunk Universal Forwarder installed. I have setup a deployment server on a linux host to manage configurations on these hosts. Recently, I have moved one of these windows hosts to another subnet. Then I found the deployment server cannot receive any phonehome from this host. Then I checked splunkd.log and splunkd_access.log, found no log with the windows host's hostname/IP observed. However, on the Linux host I run tcpdump and found the Windows is actually sending traffic to the deployment server's port 8089. So the regular phonehome message is actually sent to the deployment server but cannot "recognize" it as phonehome message. Do you have any idea what could possibly go wrong? I have actually re-installed the universal forwarder on that host but the issue is not solved. Splunk version is v8.1

Labels (4)
0 Karma

SinghK
Builder

can you telnet on port 8089 to DS?

Tags (1)
0 Karma

mvbmic
Loves-to-Learn

yes, i tried both tcpdump and telnet indeed.

0 Karma

SinghK
Builder

I meant were you able to get through to DS from the Splunk forwarder box using telnet. ror was it showing unable to connect or the error?

0 Karma

SinghK
Builder

And do you see the forwarder under  forwarder management ?

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...