Getting Data In

Why is universal forwarder phonehome not interpreted by deployment server?

mvbmic
Loves-to-Learn

I have been monitoring a few Windows hosts with Splunk Universal Forwarder installed. I have setup a deployment server on a linux host to manage configurations on these hosts. Recently, I have moved one of these windows hosts to another subnet. Then I found the deployment server cannot receive any phonehome from this host. Then I checked splunkd.log and splunkd_access.log, found no log with the windows host's hostname/IP observed. However, on the Linux host I run tcpdump and found the Windows is actually sending traffic to the deployment server's port 8089. So the regular phonehome message is actually sent to the deployment server but cannot "recognize" it as phonehome message. Do you have any idea what could possibly go wrong? I have actually re-installed the universal forwarder on that host but the issue is not solved. Splunk version is v8.1

Labels (5)
0 Karma

SinghK
Builder

can you telnet on port 8089 to DS?

Tags (1)
0 Karma

mvbmic
Loves-to-Learn

yes, i tried both tcpdump and telnet indeed.

0 Karma

SinghK
Builder

I meant were you able to get through to DS from the Splunk forwarder box using telnet. ror was it showing unable to connect or the error?

0 Karma

SinghK
Builder

And do you see the forwarder under  forwarder management ?

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...