<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connectivity between depolyment client and indexer in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86308#M22588</link>
    <description>&lt;P&gt;Ayn the issue is with all instances. I have re-enabled telnet on the network and I can telnet to and from client/server over port 23 but I cannot over port 9997. It seems that when I restart the splundd a few times I get a full update and then it all stops again so I know it can connect at some point but then it is refused...&lt;/P&gt;</description>
    <pubDate>Wed, 16 Jan 2013 15:35:23 GMT</pubDate>
    <dc:creator>mship</dc:creator>
    <dc:date>2013-01-16T15:35:23Z</dc:date>
    <item>
      <title>Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86305#M22585</link>
      <description>&lt;P&gt;I am receiving the following message in the splunkd log on my UF (windows)&lt;/P&gt;

&lt;P&gt;01-11-2013 09:47:35.129 -0500 ERROR TcpOutputFd - Connection to host=x.x.x.x:9997 failed&lt;BR /&gt;
01-11-2013 09:47:35.129 -0500 WARN  TcpOutputProc - Applying quarantine to idx=x.x.x.x:9997 numberOfFailures=2&lt;BR /&gt;
01-11-2013 09:48:04.141 -0500 INFO  TcpOutputProc - Removing quarantine from idx=x.x.x.x:9997&lt;BR /&gt;
01-11-2013 09:48:05.072 -0500 WARN  TcpOutputFd - Connect to x.x.x.x:9997 failed. No connection could be made because the target machine actively refused it.&lt;/P&gt;

&lt;P&gt;I can ping between the indexer and UF and nothing seems amiss. I cannot test with telnet b/c it is disabled. Any suggestions for troubleshooting is appreciated! Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 13:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86305#M22585</guid>
      <dc:creator>mship</dc:creator>
      <dc:date>2013-01-14T13:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86306#M22586</link>
      <description>&lt;P&gt;In order to properly troubleshoot the issue you need some kind of tool to check the connection to port 9997 on the indexer. This kind of problem is very often linked to firewall issues, or configuration issues on the indexer (port 9997 is not configured to receive data from other Splunk instances). Do you have other instances that are working properly and it's just an issue with this specific instance?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 13:59:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86306#M22586</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-14T13:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86307#M22587</link>
      <description>&lt;P&gt;Thanks Ayn. I will see if I cant get something to test it out. Peculiar thing is that everything was working fing until 2 days ago and to my knowledge nothing has changed.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jan 2013 14:25:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86307#M22587</guid>
      <dc:creator>mship</dc:creator>
      <dc:date>2013-01-14T14:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86308#M22588</link>
      <description>&lt;P&gt;Ayn the issue is with all instances. I have re-enabled telnet on the network and I can telnet to and from client/server over port 23 but I cannot over port 9997. It seems that when I restart the splundd a few times I get a full update and then it all stops again so I know it can connect at some point but then it is refused...&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2013 15:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86308#M22588</guid>
      <dc:creator>mship</dc:creator>
      <dc:date>2013-01-16T15:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86309#M22589</link>
      <description>&lt;P&gt;Update: I can now telnet to and from client/server over 9997 but still not receiving data.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2013 17:02:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86309#M22589</guid>
      <dc:creator>mship</dc:creator>
      <dc:date>2013-01-16T17:02:03Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86310#M22590</link>
      <description>&lt;P&gt;...and are you seeing the same error messages in your UF logs still?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2013 21:11:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86310#M22590</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2013-01-16T21:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86311#M22591</link>
      <description>&lt;P&gt;Yup...this morning I added the following entry to the inputs.conf file on the indexer&lt;/P&gt;

&lt;P&gt;[splunktcp://9997] connection_host = none&lt;/P&gt;

&lt;P&gt;I now seem to be receiving data...does this make sense to you?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2013 15:30:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86311#M22591</guid>
      <dc:creator>mship</dc:creator>
      <dc:date>2013-01-18T15:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86312#M22592</link>
      <description>&lt;P&gt;I solved the issue...&lt;/P&gt;

&lt;P&gt;I added the following line to the /etc/system/local/inputs.conf file on the indexer &lt;BR /&gt;
                [splunktcp://9997]&lt;BR /&gt;
                Connection_host = none&lt;/P&gt;

&lt;P&gt;I ran this by splunk support and they indicated that this is a good fix and that they are experiencing a bug in DNS reverse lookups and this is a good workaround. &lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 16:38:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86312#M22592</guid>
      <dc:creator>mship</dc:creator>
      <dc:date>2013-01-23T16:38:35Z</dc:date>
    </item>
    <item>
      <title>Re: Connectivity between depolyment client and indexer</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86313#M22593</link>
      <description>&lt;P&gt;This worked for me!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Mar 2019 23:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Connectivity-between-depolyment-client-and-indexer/m-p/86313#M22593</guid>
      <dc:creator>lrodriguez_splu</dc:creator>
      <dc:date>2019-03-25T23:54:05Z</dc:date>
    </item>
  </channel>
</rss>

