<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with Sending logs from DomainController to Splunk Intermediate forwarder. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-with-Sending-logs-from-DomainController-to-Splunk/m-p/505696#M2129</link>
    <description>&lt;P&gt;1) DC don't have any problems with cionnections to IFs on 9997 dest port.&lt;BR /&gt;2) What should be checked ?&lt;BR /&gt;Do I need compare ssl cert on IF with cert in splunk agent on DC machine ?&lt;BR /&gt;If yes I am not sure what is location of cert on DC machine&lt;BR /&gt;&lt;BR /&gt;On IF side I can see that it's in /opt/splunkforwarder/etc/apps/name_of_app/auth/cacert.pem&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2020 10:18:34 GMT</pubDate>
    <dc:creator>d4wc3k</dc:creator>
    <dc:date>2020-06-23T10:18:34Z</dc:date>
    <item>
      <title>Problem with Sending logs from DomainController to Splunk Intermediate forwarder.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-with-Sending-logs-from-DomainController-to-Splunk/m-p/505548#M2112</link>
      <description>&lt;P&gt;Hello Everyone on Splunk Forum&lt;BR /&gt;&lt;BR /&gt;I have problem with sending DC to Splunk Setup.&lt;BR /&gt;This DC machine first should send logs to IFs tier and after this place events in indexer.&lt;BR /&gt;&lt;BR /&gt;I have checked internal logs for this particular machine with "ERROR" log_level.&lt;BR /&gt;Interesting thing which has found by me is problem with 'TcpOutputFd'&lt;BR /&gt;There are folling messages&lt;/P&gt;&lt;P&gt;Connection to host=10.200.80.11:9997 failed. sock_error = 10054. SSL Error = No error&lt;BR /&gt;Connection to host=10.200.80.12:9997 failed. sock_error = 10054. SSL Error = No error&lt;BR /&gt;Connection to host=10.200.80.13:9997 failed&lt;BR /&gt;I am not very familiar with managing distributed Splunk setup - I am still learning new things.&lt;BR /&gt;&lt;BR /&gt;Could you please tell me how i can resolve this problem.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;BR /&gt;&lt;BR /&gt;BR&lt;BR /&gt;Dawid&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 16:59:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Problem-with-Sending-logs-from-DomainController-to-Splunk/m-p/505548#M2112</guid>
      <dc:creator>d4wc3k</dc:creator>
      <dc:date>2020-06-22T16:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Sending logs from DomainController to Splunk Intermediate forwarder.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-with-Sending-logs-from-DomainController-to-Splunk/m-p/505574#M2116</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/216974"&gt;@d4wc3k&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you need to check couple of things&lt;/P&gt;&lt;P&gt;1) Is there any firewall between DC &amp;amp; intermediate forwarder?&lt;/P&gt;&lt;P&gt;you can check this from DC doing telnet forwarderip:9997&lt;/P&gt;&lt;P&gt;2) IS ssl enabled for this transfer? If so certs should match&lt;/P&gt;&lt;P&gt;you can check this in "inputs.conf" on intermediate forwarder&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jun 2020 18:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Problem-with-Sending-logs-from-DomainController-to-Splunk/m-p/505574#M2116</guid>
      <dc:creator>anilchaithu</dc:creator>
      <dc:date>2020-06-22T18:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Sending logs from DomainController to Splunk Intermediate forwarder.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-with-Sending-logs-from-DomainController-to-Splunk/m-p/505696#M2129</link>
      <description>&lt;P&gt;1) DC don't have any problems with cionnections to IFs on 9997 dest port.&lt;BR /&gt;2) What should be checked ?&lt;BR /&gt;Do I need compare ssl cert on IF with cert in splunk agent on DC machine ?&lt;BR /&gt;If yes I am not sure what is location of cert on DC machine&lt;BR /&gt;&lt;BR /&gt;On IF side I can see that it's in /opt/splunkforwarder/etc/apps/name_of_app/auth/cacert.pem&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 10:18:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Problem-with-Sending-logs-from-DomainController-to-Splunk/m-p/505696#M2129</guid>
      <dc:creator>d4wc3k</dc:creator>
      <dc:date>2020-06-23T10:18:34Z</dc:date>
    </item>
  </channel>
</rss>

