Changes were made to the indexer server. By default, outbound connections from the forwarder server do not normally need firewall changes. The indexer will need to have the scope for the forwarder as well as the ports in use.
... View more
I had something similar. To fix, I opened the Firewall settings on the Splunk Server and added the Splunk Receiver port (9911) and Splunk Admin Port (8000) to the allowed exceptions and all worked fine.
... View more