<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with forwarder. Couldn't complete HTTP request:  Connection timed out in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329538#M61108</link>
    <description>&lt;P&gt;go to &lt;BR /&gt;
Etc/system/local/inputs.conf&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;BR /&gt;
connection_host = none&lt;/P&gt;

&lt;P&gt;restart Splunk server and it will be fixed. DNS is holding it all up.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Dec 2017 08:54:43 GMT</pubDate>
    <dc:creator>mayurr98</dc:creator>
    <dc:date>2017-12-08T08:54:43Z</dc:date>
    <item>
      <title>Issue with forwarder. Couldn't complete HTTP request:  Connection timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329533#M61103</link>
      <description>&lt;P&gt;I have several forwarders, all installed on Ubuntu 14.04 boxes.  One of them stopped working but the rest are fine.  After troubleshooting, the only difference on the one not working from the others is that when I try these commands:&lt;/P&gt;

&lt;P&gt;./splunk list forward-server&lt;BR /&gt;
./splunk show deploy-poll&lt;/P&gt;

&lt;P&gt;I get an error which is "Couldn't complete HTTP request:  Connection timed out"&lt;/P&gt;

&lt;P&gt;These commands work on my other forwarders and immediately ask me for my credentials.  When I try these commands on the box that isn't working, it takes about 30 seconds and then gives me that error.  I can't find any information about this error online (I find the error but not anything about why a connection would time out.  The outputs.conf file is the same on every box and any other .conf file I know about is the same.  &lt;/P&gt;

&lt;P&gt;Anyone know what would cause this or even a log file I can view that might give me a clue?  Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 19:49:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329533#M61103</guid>
      <dc:creator>tribunal</dc:creator>
      <dc:date>2017-12-06T19:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with forwarder. Couldn't complete HTTP request:  Connection timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329534#M61104</link>
      <description>&lt;P&gt;Cheerful place to start at &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Troubleshooting/Cantfinddata"&gt;I can't find my data!&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Especially the section which says - &lt;/P&gt;

&lt;P&gt;-- Are my forwarders connecting to my receiver? Which IP addresses are connecting to Splunk as inputs, and how many times is each IP logged in metrics.log?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 20:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329534#M61104</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-12-06T20:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with forwarder. Couldn't complete HTTP request:  Connection timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329535#M61105</link>
      <description>&lt;P&gt;I'd check the ports on the box.  When it seems like a box isn't listening, it's possible that it isn't listening.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 21:40:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329535#M61105</guid>
      <dc:creator>DalJeanis</dc:creator>
      <dc:date>2017-12-06T21:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with forwarder. Couldn't complete HTTP request:  Connection timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329536#M61106</link>
      <description>&lt;P&gt;Thank you for the input.  I ran the command "index=_internal source=&lt;EM&gt;metrics.log&lt;/EM&gt; tcpin_connections | stats count by sourceIp" in Splunk and the IP address of the box is showing up.  Does this mean that it is sending something to Splunk but Splunk is not displaying the events?  What could cause Splunk to get events but not display them?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:06:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329536#M61106</guid>
      <dc:creator>tribunal</dc:creator>
      <dc:date>2020-09-29T17:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with forwarder. Couldn't complete HTTP request:  Connection timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329537#M61107</link>
      <description>&lt;P&gt;Make sure that a firewall is not running and blocking ports.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 06:26:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329537#M61107</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-12-08T06:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with forwarder. Couldn't complete HTTP request:  Connection timed out</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329538#M61108</link>
      <description>&lt;P&gt;go to &lt;BR /&gt;
Etc/system/local/inputs.conf&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;BR /&gt;
connection_host = none&lt;/P&gt;

&lt;P&gt;restart Splunk server and it will be fixed. DNS is holding it all up.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 08:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-with-forwarder-Couldn-t-complete-HTTP-request-Connection/m-p/329538#M61108</guid>
      <dc:creator>mayurr98</dc:creator>
      <dc:date>2017-12-08T08:54:43Z</dc:date>
    </item>
  </channel>
</rss>

