Make sure you have this line in your iptable
cat /etc/sysconfig/iptables
vi /etc/sysconfig/iptables
-A INPUT -m state --state NEW -m tcp -p tcp --dport 9997 -j ACCEPT
... View more
Linebreaking must be done on an indexer, it's a parse time event. Universal forwarders do not parse data (Except in some situations around Indexed Extractions, but that doesn't apply here).
Try moving your props.conf to your indexers.
... View more