Getting Data In

Why is universal forwarder phonehome not interpreted by deployment server?

mvbmic
Loves-to-Learn

I have been monitoring a few Windows hosts with Splunk Universal Forwarder installed. I have setup a deployment server on a linux host to manage configurations on these hosts. Recently, I have moved one of these windows hosts to another subnet. Then I found the deployment server cannot receive any phonehome from this host. Then I checked splunkd.log and splunkd_access.log, found no log with the windows host's hostname/IP observed. However, on the Linux host I run tcpdump and found the Windows is actually sending traffic to the deployment server's port 8089. So the regular phonehome message is actually sent to the deployment server but cannot "recognize" it as phonehome message. Do you have any idea what could possibly go wrong? I have actually re-installed the universal forwarder on that host but the issue is not solved. Splunk version is v8.1

Labels (4)
0 Karma

SinghK
Builder

can you telnet on port 8089 to DS?

Tags (1)
0 Karma

mvbmic
Loves-to-Learn

yes, i tried both tcpdump and telnet indeed.

0 Karma

SinghK
Builder

I meant were you able to get through to DS from the Splunk forwarder box using telnet. ror was it showing unable to connect or the error?

0 Karma

SinghK
Builder

And do you see the forwarder under  forwarder management ?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...