Getting Data In

Why is universal forwarder phonehome not interpreted by deployment server?

mvbmic
Loves-to-Learn

I have been monitoring a few Windows hosts with Splunk Universal Forwarder installed. I have setup a deployment server on a linux host to manage configurations on these hosts. Recently, I have moved one of these windows hosts to another subnet. Then I found the deployment server cannot receive any phonehome from this host. Then I checked splunkd.log and splunkd_access.log, found no log with the windows host's hostname/IP observed. However, on the Linux host I run tcpdump and found the Windows is actually sending traffic to the deployment server's port 8089. So the regular phonehome message is actually sent to the deployment server but cannot "recognize" it as phonehome message. Do you have any idea what could possibly go wrong? I have actually re-installed the universal forwarder on that host but the issue is not solved. Splunk version is v8.1

Labels (5)
0 Karma

SinghK
Builder

can you telnet on port 8089 to DS?

Tags (1)
0 Karma

mvbmic
Loves-to-Learn

yes, i tried both tcpdump and telnet indeed.

0 Karma

SinghK
Builder

I meant were you able to get through to DS from the Splunk forwarder box using telnet. ror was it showing unable to connect or the error?

0 Karma

SinghK
Builder

And do you see the forwarder under  forwarder management ?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...