Getting Data In

Why is universal forwarder phonehome not interpreted by deployment server?

mvbmic
Loves-to-Learn

I have been monitoring a few Windows hosts with Splunk Universal Forwarder installed. I have setup a deployment server on a linux host to manage configurations on these hosts. Recently, I have moved one of these windows hosts to another subnet. Then I found the deployment server cannot receive any phonehome from this host. Then I checked splunkd.log and splunkd_access.log, found no log with the windows host's hostname/IP observed. However, on the Linux host I run tcpdump and found the Windows is actually sending traffic to the deployment server's port 8089. So the regular phonehome message is actually sent to the deployment server but cannot "recognize" it as phonehome message. Do you have any idea what could possibly go wrong? I have actually re-installed the universal forwarder on that host but the issue is not solved. Splunk version is v8.1

Labels (5)
0 Karma

SinghK
Builder

can you telnet on port 8089 to DS?

Tags (1)
0 Karma

mvbmic
Loves-to-Learn

yes, i tried both tcpdump and telnet indeed.

0 Karma

SinghK
Builder

I meant were you able to get through to DS from the Splunk forwarder box using telnet. ror was it showing unable to connect or the error?

0 Karma

SinghK
Builder

And do you see the forwarder under  forwarder management ?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...