Getting Data In

Why am I unable to connect my Windows universal forwarder to the Sandbox?

lehrfeld
Path Finder

All -

I would like to experiment with Splunk Cloud but I am having an issue getting any data into my sandbox.

I installed the windows UF on my laptop and told it to forward windows events to my cloud instance (prd-p-mycloud.cloud.splunk.com:9997). I then downloaded and installed the credentials from the UF App in Splunk Cloud.

All the documentation I have been able to find indicates that is all I need to do. But for some reason in my splunkd log file I am getting the WARN TcpOutputProc - Cooked connection to ip=x.x.x.x:9997 timed out error.

When I run a netstat, I get an ESTABLISHED connection to port 9997 with Splunk Cloud. I even went so far as to turn off my Windows firewall and still nothing.

Any thoughts or docs that I may have missed to set this up?

Thanks!

Mike

1 Solution

ppablo
Retired

Hi @lehrfeld

Here's a previous Answers post covering the process for setting up a forwarder for the Sandbox that might be helpful. There is a note specifically for Windows forwarders at the very bottom of the answer. Not sure if that's part of the issue you're experiencing, but worth checking out. http://answers.splunk.com/answers/214420/how-do-i-setup-a-splunk-cloud-trial-sandbox-forwar.html

View solution in original post

ppablo
Retired

Hi @lehrfeld

Here's a previous Answers post covering the process for setting up a forwarder for the Sandbox that might be helpful. There is a note specifically for Windows forwarders at the very bottom of the answer. Not sure if that's part of the issue you're experiencing, but worth checking out. http://answers.splunk.com/answers/214420/how-do-i-setup-a-splunk-cloud-trial-sandbox-forwar.html

Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...