Security

Searchhead not able to communicate (tcp handshake with indexer on port 9997) just showing SYn packets captured

thaghost99
Path Finder

hi, i am setting up a search head/indexer setup. 

i have port 9997 listening on indexer, i configured searchhead to send to indexer (since i have the files being sent to search head). 

i can see the syn packets being sent from search head to indexer, but thats about it. i am not sure what the indexer is doing about it, its not sending any error back or anything.

capture tcp dump on indexer

thaghost99_2-1706655180287.png

 

thaghost99_0-1706654929696.png

 

capture tcp dump and logs from searchhead.

 

thaghost99_1-1706655107406.png

let me know what i need to do to fix this. 🙂 thank you in advanced

 

0 Karma
1 Solution

thaghost99
Path Finder

yeah its was 100% my fault. i forgot to disable the local firewall on the server. 😞

 

thank you though for the help. 

View solution in original post

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. I don't understand what you mean by "I have files sent to search head". If you're trying to use your SH also as a forwarder... well, that's not a good practice. But it shouldn't be the cause of the problem here.

2. Since you're sending SYNs, the indexer is listening on the port and apparently even gets those SYNs on the wire, there are two possible explanations - either your local firewall (iptables? firewalld? that new fancy nftables?) is filtering the packets or you have badly configured routing and packets are dropped by rp_filter.

0 Karma

thaghost99
Path Finder

yeah its was 100% my fault. i forgot to disable the local firewall on the server. 😞

 

thank you though for the help. 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...