Splunk Enterprise

Usin Splunk forwarder

abe
New Member

Hi

I have installed a Splunk Forwarder on a remote computer and I chose wmi as data input in the main server. But when I want to find a log I get the message that remote computer is not reachable. This is while I have defined firewall rules for Splunk dynamic ports. Would you please help me?

Labels (1)
0 Karma

datadevops
Path Finder

Hi there,

The remote Splunk Forwarder might not be reachable due to:

  1. Connectivity: Ping the remote machine and check WMI service status.
  2. WMI configuration: Verify inputs.conf settings (server, namespace, credentials, source path).
  3. Firewall: Ensure firewall allows connections on Splunk dynamic ports (9997, 8089) and WMI port (135).
  4. Authentication: Double-check Splunk credentials have WMI access on the remote machine.
  5. Logs: Review Splunk logs on both machines for errors or warnings.

If these don't help, consider:

  • Testing WMI connection manually using wbemtest.exe.
  • Enabling debug logging in inputs.conf for more detailed logs.
  • Using file inputs instead of WMI if necessary.

Please provide more details (Splunk version, error messages) if you need further assistance.

~ If the reply helps, a Karma upvote would be appreciated

0 Karma
Get Updates on the Splunk Community!

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...