<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spunk Forwarder troubleshooting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344372#M63361</link>
    <description>&lt;P&gt;Hello, we are already on a production environment. Hundreds of Splunk UFs are already reporting to our Deployment client so yeah, already done with those steps.&lt;/P&gt;

&lt;P&gt;Made some edits to make things more clear.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2017 13:32:38 GMT</pubDate>
    <dc:creator>lloydknight</dc:creator>
    <dc:date>2017-06-13T13:32:38Z</dc:date>
    <item>
      <title>Spunk Forwarder troubleshooting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344368#M63357</link>
      <description>&lt;P&gt;Here's the scenario:&lt;/P&gt;

&lt;P&gt;UniversalForwarder1 already forwarding logs to Indexer1.&lt;BR /&gt;
UniversalForwarder1's IP is 10.226.xx.xx and Indexer1's IP is 10.251.xx.xx&lt;BR /&gt;
&lt;STRONG&gt;Connectivity:&lt;/STRONG&gt;&lt;BR /&gt;
Firewall is good. Can Telnet at port9997 from UniversalForwarder1 to Indexer1.&lt;BR /&gt;
&lt;STRONG&gt;Splunkd logs:&lt;/STRONG&gt;&lt;BR /&gt;
Logs are good, no errors and whatsoever. Indexing OS logs from TA_nix_add-on.&lt;/P&gt;

&lt;P&gt;UniversalForwarder1 to forward logs to Indexer2.&lt;BR /&gt;
UniversalForwarder1's IP is 10.226.xx.xx and Indexer2's IP is 10.2226.xx.xx&lt;BR /&gt;
&lt;STRONG&gt;Connectivity:&lt;/STRONG&gt;&lt;BR /&gt;
No need for Firewall as they're directly connected (p2p). Can Telnet at port9997 from UniversalForwarder1 to Indexer2. Traceroute has 2 hops only as expected.&lt;BR /&gt;
&lt;STRONG&gt;Splunkd logs:&lt;/STRONG&gt;&lt;BR /&gt;
No internal logs to troubleshoot. How is that? Not Indexing OS logs from TA_nix_add-on even though UniversalForwarder1 is sending logs to Indexer1 and Indexer1 is indexing logs from it. No logs from Indexer2.&lt;/P&gt;

&lt;P&gt;Anyone?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:26:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344368#M63357</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2020-09-29T14:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk Forwarder troubleshooting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344369#M63358</link>
      <description>&lt;P&gt;Check if the DNS is resolved when the forwarder sends data to indexer. Are there any unknown host error at the network level ? &lt;/P&gt;

&lt;P&gt;More info shall help me address your problem. &lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 07:43:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344369#M63358</guid>
      <dc:creator>nit123</dc:creator>
      <dc:date>2017-06-13T07:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk Forwarder troubleshooting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344370#M63359</link>
      <description>&lt;P&gt;For the Network level, ping, traceroute, and telnet were good.  what other tests should I do here?&lt;/P&gt;

&lt;P&gt;checked %SPLUNK/var/log/splunk/splunkd.log on the server with installed Forwarder, Forwarder is connected to the Indexer1 but no logs pertaining to Indexer2. &lt;/P&gt;

&lt;P&gt;It's as if the error is indexer IP and port was not defined in outputs.conf but quadruple checked it already.&lt;/P&gt;

&lt;P&gt;I want to provide more info but I'm stuck as there are no logs &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;any recommendations?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 08:58:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344370#M63359</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-06-13T08:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk Forwarder troubleshooting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344371#M63360</link>
      <description>&lt;P&gt;Just to reiterate that you have done the following. Kindly confirm &lt;/P&gt;

&lt;P&gt;1) Setup a Forwarder&lt;/P&gt;

&lt;P&gt;To enable forwarding, navigate to  Settings -&amp;gt; Forwarding &amp;amp; Receiving -&amp;gt; Configure Forwarding -&amp;gt; New &amp;amp; set IP address of the splunk instance to forward data to.&lt;/P&gt;

&lt;P&gt;2) Setup a Indexer&lt;/P&gt;

&lt;P&gt;All full Splunk Enterprise instances serve as indexers by default. &lt;/P&gt;

&lt;P&gt;To forward remote data to an indexer, you use forwarders, which are Splunk Enterprise instances that receive data inputs and then consolidate and send the data to a Splunk Enterprise indexer. &lt;BR /&gt;
To enable receiver at Indexer, &lt;/P&gt;

&lt;P&gt;Navigate to Settings -&amp;gt; Forwarding &amp;amp; Receiving -&amp;gt;Configure Receiving -&amp;gt; New &amp;amp; add IP address of splunk stance that will forward data.&lt;/P&gt;

&lt;P&gt;Have you followed the same steps ? &lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 12:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344371#M63360</guid>
      <dc:creator>nit123</dc:creator>
      <dc:date>2017-06-13T12:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk Forwarder troubleshooting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344372#M63361</link>
      <description>&lt;P&gt;Hello, we are already on a production environment. Hundreds of Splunk UFs are already reporting to our Deployment client so yeah, already done with those steps.&lt;/P&gt;

&lt;P&gt;Made some edits to make things more clear.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 13:32:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344372#M63361</guid>
      <dc:creator>lloydknight</dc:creator>
      <dc:date>2017-06-13T13:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: Spunk Forwarder troubleshooting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344373#M63362</link>
      <description>&lt;P&gt;Alright. So are you indexing data on the forwarder as well or only forwarding data to indexer.&lt;BR /&gt;&lt;BR /&gt;
Without the logs having possible errors, we might not zero down to a root cause &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 05:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Spunk-Forwarder-troubleshooting/m-p/344373#M63362</guid>
      <dc:creator>nit123</dc:creator>
      <dc:date>2017-06-14T05:42:20Z</dc:date>
    </item>
  </channel>
</rss>

