<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Connect to my server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19379#M2749</link>
    <description>&lt;P&gt;thanks for the quick reply sdanniels&lt;/P&gt;

&lt;P&gt;ah yes that's the output.conf on the forwarder. I didn't have that setting on the indexer inputs.conf so it now looks like this:&lt;/P&gt;

&lt;P&gt;[default] host = winxphostname&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;/P&gt;

&lt;P&gt;still can;t see anything in the deployment monitor and now I'm not sure where to look for clues as to what's wrong &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jul 2012 12:29:03 GMT</pubDate>
    <dc:creator>rgill90</dc:creator>
    <dc:date>2012-07-27T12:29:03Z</dc:date>
    <item>
      <title>Connect to my server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19377#M2747</link>
      <description>&lt;P&gt;Hi All &lt;/P&gt;

&lt;P&gt;I'm trying Splunk for the first time - I'm sifting through the documentation and finding it difficult to ascertain how to install forwarder and do a very basic config with an indexer.&lt;/P&gt;

&lt;P&gt;Installed it on my win xp desktop as the indexer and installed the forwader on a test Linux machine. The linux forwarder inputs.conf looks like this:&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = hostnameofwindowslaptop_9997&lt;/P&gt;

&lt;P&gt;[tcpout:hostnameofwindowslaptop_9997]&lt;BR /&gt;
server = hostnameofwindowslaptop:9997&lt;/P&gt;

&lt;P&gt;[tcpout-server://hostnameofwindowslaptop:9997]&lt;/P&gt;

&lt;P&gt;in the windows server logs i constantly get this:&lt;/P&gt;

&lt;P&gt;07-27-2012 11:40:39.274 +0100 ERROR TcpOutputFd - Connection to host=forwarderIP:9997 failed&lt;BR /&gt;
07-27-2012 11:40:39.274 +0100 WARN  TcpOutputProc - Applying quarantine to idx=forwarderIP:9997 numberOfFailures=11&lt;/P&gt;

&lt;P&gt;...and on the forwarder in the splunkd.log i get exactly the same error messages.&lt;/P&gt;

&lt;P&gt;Can anyone give me any pointers to troubleshoot this? I've tried searching for errors in the web gui search bar over the passed 24 hours and it tells me there's no errors.  My forwarder doesn't show in the 'datasources' bit on the search screen either.  Bit stumped &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;  Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 10:48:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19377#M2747</guid>
      <dc:creator>rgill90</dc:creator>
      <dc:date>2012-07-27T10:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Connect to my server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19378#M2748</link>
      <description>&lt;P&gt;Do you mean outputs.conf on the forwarder?  The inputs file on the forwarder will configure what you are monitoring for data, not the connection back to the indexer server. What you have above looks like configurations i'd expects in outputs.conf on the forwarder. &lt;/P&gt;

&lt;P&gt;Check on the indexer inputs.conf to make sure you have this setting as well:&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 11:11:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19378#M2748</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-07-27T11:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Connect to my server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19379#M2749</link>
      <description>&lt;P&gt;thanks for the quick reply sdanniels&lt;/P&gt;

&lt;P&gt;ah yes that's the output.conf on the forwarder. I didn't have that setting on the indexer inputs.conf so it now looks like this:&lt;/P&gt;

&lt;P&gt;[default] host = winxphostname&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;/P&gt;

&lt;P&gt;still can;t see anything in the deployment monitor and now I'm not sure where to look for clues as to what's wrong &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 12:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19379#M2749</guid>
      <dc:creator>rgill90</dc:creator>
      <dc:date>2012-07-27T12:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Connect to my server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19380#M2750</link>
      <description>&lt;P&gt;well it seems i just had to wait and be patient....suddenly started appearing...gawd knows why / how but the only change i did was the one above&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 12:43:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19380#M2750</guid>
      <dc:creator>rgill90</dc:creator>
      <dc:date>2012-07-27T12:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: Connect to my server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19381#M2751</link>
      <description>&lt;P&gt;Do you have any events being indexed?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 13:07:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Connect-to-my-server/m-p/19381#M2751</guid>
      <dc:creator>iunderwood</dc:creator>
      <dc:date>2012-07-27T13:07:13Z</dc:date>
    </item>
  </channel>
</rss>

