Hi ammul440,
the error you report says that you have to open firewall routes between targets and Splunk server on port 9997 for data and on 8089 for management (if you use Splunk server also as a Deployment server.
This is always the first check to do before to install a Universal Forwarder.
About the search I suggested, it has the objective to see if the target is connected to the Indexer.
I don't understand when you speak of a "separate node", target and Splunk server are on the same server?
Ciao.
Giuseppe
... View more