Dear All, Unable to send data from universal forwarder, to Splunk Enterprise i have minimal knowledge in Splunk I'm trying to configure universal forwarder but unable to success could you please help me in this regards Please find the below my configurations i am using Splunk Enterprise 9.0 and universal forwarder version 9.1.1using Cent OS 7.0 inputs.conf [root@Universalforwarders local]# [monitor:///var/log/messages] index=os disabled=0 outputs.conf [root@Universalforwarders local]# [tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] [server://192.168.122.1:9997] i used following command to check port status: netstat -an | grep 9997 tcp 0 0 0.0.0.0:9997 0.0.0.0:* LISTEN localhost.localdomain --- my Splunk enterprise instance 127.0.0.1 --- my Splunk Universal forwarder i want to know where i am doing mistake would be appreciate your kind support thanks in advance
... View more