Hi @dijon000, there can be many reasons because an Indexer doesn't receive logs from a Universal Forwarder, but the approach uninstall/install isn't a good idea because usually it doesn't solves the issue! Anyway, do you still have the UF in the list on installed application on Windows? if yes, you could try to install it again, if not you can delete the remaining files and install it again. If the error is still present and you have a valid license, open a case to Splunk Support. About the issue of not sending logs to Indexer, at first check if you're receiving logs with a simple search: index=_internal host=your_universal_forwarder_host if you have logs, the UF is correctly installed and configured, Then you see the UF in Forwarders management only if you configured Deployment Server on UF. if not there could be many reasons: did you configured receiver on Indexer? [Settings > Forwarding and Receiving > Receiving] did you configured outputs on UF? is the indexer reachable from the UF or there are intermediate firewalls? for more infos see at https://docs.splunk.com/Documentation/Splunk/9.0.4/Forwarding/Aboutforwardingandreceivingdata Ciao. Giuseppe
... View more