<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarder not compressing despite being told to do so in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-not-compressing-despite-being-told-to-do-so/m-p/63783#M12822</link>
    <description>&lt;P&gt;I am  also seeing the same behavior. My compression settings are also set the same as yours. Were you able to find an answer?&lt;/P&gt;</description>
    <pubDate>Wed, 09 Jan 2013 17:56:46 GMT</pubDate>
    <dc:creator>rodman</dc:creator>
    <dc:date>2013-01-09T17:56:46Z</dc:date>
    <item>
      <title>forwarder not compressing despite being told to do so</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-not-compressing-despite-being-told-to-do-so/m-p/63781#M12820</link>
      <description>&lt;P&gt;Hi There. I have 2 matching forwarders pointed to an indexer. One compresses, one doesn't. Any ideas why?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Machine that works&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cat /opt/splunk/etc/system/local/outputs.conf 
[tcpout]
defaultGroup = my_indexers
indexAndForward = true

[tcpout:my_indexers]
compressed = true
server = splunklog:29000

[tcpout-server://splunklog:29000]
compressed = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Machine that doesn't work&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cat /opt/splunk/etc/system/local/outputs.conf 
[tcpout]
defaultGroup = my_indexers
indexAndForward = true

[tcpout:my_indexers]
compressed = true
server = splunklog:29001

[tcpout-server://splunklog:29001]
compressed = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Indexer (machine that receives)&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cat /opt/splunk/etc/system/local/inputs.conf 
[default]
host = splunk.***********.com

[splunktcp://29000]
compressed = true
enableS2SHeartbeat = true

[splunktcp://29001]
compressed = true
enableS2SHeartbeat = true
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Log that proves it (10.&lt;EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;.&lt;/EM&gt;&lt;STRONG&gt;.101 is the machine that doesn't send compressed)&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;tail /opt/splunk/var/logs/splunk/splunkd.log
10-04-2010 19:55:16.756 ERROR TcpInputProc - Received unrecognized signature --splunk-cooked-mode-v2--! from hostname=10.***.****.101, ip=10.***.****.101, port=41119
10-04-2010 19:55:16.756 INFO  TcpInputProc - Hostname=10.***.****.101 closed connection
10-04-2010 19:55:47.771 INFO  TcpInputProc - Connection in cooked mode from 10.***.****.101
10-04-2010 19:56:18.756 ERROR PipelineDataInput - Mismatch in configuration between forwarder and indexer. Expecting compressed data, but forwarder configured to send without compression
10-04-2010 19:56:18.756 ERROR TcpInputProc - Received unrecognized signature --splunk-cooked-mode-v2--! from hostname=10.***.****.101, ip=10.***.****.101, port=41120
10-04-2010 19:56:18.756 INFO  TcpInputProc - Hostname=10.***.****.101 closed connection
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 05 Oct 2010 09:05:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-not-compressing-despite-being-told-to-do-so/m-p/63781#M12820</guid>
      <dc:creator>summitcove</dc:creator>
      <dc:date>2010-10-05T09:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder not compressing despite being told to do so</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-not-compressing-despite-being-told-to-do-so/m-p/63782#M12821</link>
      <description>&lt;P&gt;I'm having the same problem. Did you manage to fix it?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2010 04:42:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-not-compressing-despite-being-told-to-do-so/m-p/63782#M12821</guid>
      <dc:creator>davidbrai</dc:creator>
      <dc:date>2010-12-13T04:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: forwarder not compressing despite being told to do so</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/forwarder-not-compressing-despite-being-told-to-do-so/m-p/63783#M12822</link>
      <description>&lt;P&gt;I am  also seeing the same behavior. My compression settings are also set the same as yours. Were you able to find an answer?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 17:56:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/forwarder-not-compressing-despite-being-told-to-do-so/m-p/63783#M12822</guid>
      <dc:creator>rodman</dc:creator>
      <dc:date>2013-01-09T17:56:46Z</dc:date>
    </item>
  </channel>
</rss>

