<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Cloud Trial: Why am I getting &amp;quot;ERROR TcpOutputFd - Connection to host=(splunk-cloud-ip):9997 failed&amp;quot; after setting up a universal forwarder on our EC2 instance? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237437#M46114</link>
    <description>&lt;P&gt;I have the same problem ... anyone can help us ?&lt;/P&gt;

&lt;P&gt;Best &lt;BR /&gt;
Giovanni&lt;/P&gt;</description>
    <pubDate>Wed, 18 Nov 2015 08:56:29 GMT</pubDate>
    <dc:creator>Shinpo</dc:creator>
    <dc:date>2015-11-18T08:56:29Z</dc:date>
    <item>
      <title>Splunk Cloud Trial: Why am I getting "ERROR TcpOutputFd - Connection to host=(splunk-cloud-ip):9997 failed" after setting up a universal forwarder on our EC2 instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237435#M46112</link>
      <description>&lt;P&gt;I signed up for a Splunk Cloud trial, and set up a universal forwarder on one of our EC2 instances. However, I keep getting this in splunkd.log:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR TcpOutputFd - Connection to host=[ip address of input server]:9997 failed
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I tried telnet to the ip/port and it was successful, so there should be no network-related issues. &lt;/P&gt;

&lt;P&gt;If I go in the admin console to &lt;STRONG&gt;Settings-&amp;gt;Forwarding and Receiving&lt;/STRONG&gt; I see the message:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;There was an error retrieving the configuration, can not process this page
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Is there some additional configuration on either the admin or on our EC2 instance (universal forwarder) to get this to work? Or does the Splunk Cloud trial not allow contributing data to the instance?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2015 04:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237435#M46112</guid>
      <dc:creator>pjoiner</dc:creator>
      <dc:date>2015-11-17T04:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Trial: Why am I getting "ERROR TcpOutputFd - Connection to host=(splunk-cloud-ip):9997 failed" after setting up a universal forwarder on our EC2 instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237436#M46113</link>
      <description>&lt;P&gt;BTW the universal forwarder is running on Amazon Linux with the latest OS updates.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 01:13:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237436#M46113</guid>
      <dc:creator>pjoiner</dc:creator>
      <dc:date>2015-11-18T01:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Trial: Why am I getting "ERROR TcpOutputFd - Connection to host=(splunk-cloud-ip):9997 failed" after setting up a universal forwarder on our EC2 instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237437#M46114</link>
      <description>&lt;P&gt;I have the same problem ... anyone can help us ?&lt;/P&gt;

&lt;P&gt;Best &lt;BR /&gt;
Giovanni&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 08:56:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237437#M46114</guid>
      <dc:creator>Shinpo</dc:creator>
      <dc:date>2015-11-18T08:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Trial: Why am I getting "ERROR TcpOutputFd - Connection to host=(splunk-cloud-ip):9997 failed" after setting up a universal forwarder on our EC2 instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237438#M46115</link>
      <description>&lt;P&gt;Could you give us a little more information? &lt;CODE&gt;outputs.conf&lt;/CODE&gt; of the forwarder and &lt;CODE&gt;inputs.conf&lt;/CODE&gt; of the receiver? and maybe the &lt;CODE&gt;$SPLUNK_HOME/etc/apps/search/metadata/local.meta&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2015 15:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237438#M46115</guid>
      <dc:creator>Sebastian2</dc:creator>
      <dc:date>2015-11-18T15:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Trial: Why am I getting "ERROR TcpOutputFd - Connection to host=(splunk-cloud-ip):9997 failed" after setting up a universal forwarder on our EC2 instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237439#M46116</link>
      <description>&lt;P&gt;outputs.conf &lt;BR /&gt;
&lt;CODE&gt;/opt/splunkforwarder/etc/system/local/outputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout]
defaultGroup = splunkcloud
disabled = false
maxQueueSize = 1500
indexAndForward = false
[tcpout:splunkcloud]
server = input-prd-p-pdsmk7bx6vlg.cloud.splunk.com:9997
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;inputs.conf&lt;BR /&gt;
&lt;CODE&gt;/opt/splunkforwarder/etc/system/local/inputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = SyslogSRV
[monitor:///var/log/TEST-SYSLOG/test-sysLog.log]
[splunktcp-ssl://9997]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;local.meta&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[inputs/monitor%3A%2F%2F%2Fvar%2Flog%2FTEST-SYSLOG%2Ftest-sysLog.log]
owner = splunk-system-user
version = 6.3.1
modtime = 1447503002.498094000

[inputs/monitor%3A%2F%2F%2Fvar%2Flog%2Fsyslog]
owner = admin
version = 6.3.1
modtime = 1447516194.527718000

[inputs/monitor%3A%2F%2F%2Fvar%2Flog]
owner = admin
version = 6.3.1
modtime = 1447767752.634803000

[inputs/splunktcp%3A%2F%2F9997]
owner = admin
version = 6.3.1
modtime = 1447857226.751613000
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 18 Nov 2015 18:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237439#M46116</guid>
      <dc:creator>Shinpo</dc:creator>
      <dc:date>2015-11-18T18:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Cloud Trial: Why am I getting "ERROR TcpOutputFd - Connection to host=(splunk-cloud-ip):9997 failed" after setting up a universal forwarder on our EC2 instance?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237440#M46117</link>
      <description>&lt;P&gt;I found the cause of my issue. Although I could telnet to port 9997, the problem was that the EC2 instance did not have a direct path to the internet (i.e. was using a proxy). To test I used a different EC2 that had a direct path to the internet, and the forwarder started working correctly. &lt;/P&gt;

&lt;P&gt;I had been told that there was no internet proxy/firewall for the first machine I had tried, but that information was not correct.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 02:35:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Cloud-Trial-Why-am-I-getting-quot-ERROR-TcpOutputFd/m-p/237440#M46117</guid>
      <dc:creator>pjoiner</dc:creator>
      <dc:date>2015-11-19T02:35:37Z</dc:date>
    </item>
  </channel>
</rss>

