<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to start Splunk forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386917#M69405</link>
    <description>&lt;OL&gt;
&lt;LI&gt;Could you please share some more information from splunkd.log&lt;/LI&gt;
&lt;LI&gt;Could be a possibility something is wrong with log.cfg file &amp;lt; PATH: $SPLUNK_HOME/etc/log.cfg &amp;gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Fri, 12 Jul 2019 13:15:06 GMT</pubDate>
    <dc:creator>sunnyb147</dc:creator>
    <dc:date>2019-07-12T13:15:06Z</dc:date>
    <item>
      <title>Unable to start Splunk forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386916#M69404</link>
      <description>&lt;P&gt;Maybe someone here could help me as i have issue on starting the SPLUNK forwarder.&lt;BR /&gt;
Here's the full error upon trying to start the forwarder&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
        Management port has been set disabled; cli support for this configuration is currently incomplete.&lt;BR /&gt;
        Checking conf files for typos...        Done&lt;BR /&gt;
All preliminary checks passed.&lt;/P&gt;

&lt;P&gt;Starting splunk server daemon (splunkd)...&lt;BR /&gt;
Error loading logging config file&lt;/P&gt;

&lt;P&gt;Timed out waiting for splunkd to start.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 12:28:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386916#M69404</guid>
      <dc:creator>Manilyn</dc:creator>
      <dc:date>2019-07-12T12:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start Splunk forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386917#M69405</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Could you please share some more information from splunkd.log&lt;/LI&gt;
&lt;LI&gt;Could be a possibility something is wrong with log.cfg file &amp;lt; PATH: $SPLUNK_HOME/etc/log.cfg &amp;gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 12 Jul 2019 13:15:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386917#M69405</guid>
      <dc:creator>sunnyb147</dc:creator>
      <dc:date>2019-07-12T13:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start Splunk forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386918#M69406</link>
      <description>&lt;P&gt;07-08-2019 17:22:55.806 -0500 WARN  Logger - $SPLUNK_HOME/etc/log.cfg:263: Pa&lt;BR /&gt;
rse error at "appender.idata_ResourceUsage.serialization=JSON"&lt;BR /&gt;
07-08-2019 17:22:55.807 -0500 WARN  Logger - $SPLUNK_HOME/etc/log.cfg:273: Pa&lt;BR /&gt;
rse error at "appender.idata_DiskObjects.serialization=JSON"&lt;BR /&gt;
07-08-2019 17:25:56.521 -0500 WARN  Logger - $SPLUNK_HOME/etc/log.cfg:263: Pa&lt;BR /&gt;
rse error at "appender.idata_ResourceUsage.serialization=JSON"&lt;BR /&gt;
07-08-2019 17:25:56.522 -0500 WARN  Logger - $SPLUNK_HOME/etc/log.cfg:273: Pa&lt;BR /&gt;
rse error at "appender.idata_DiskObjects.serialization=JSON"&lt;BR /&gt;
07-12-2019 07:00:43.255 -0500 WARN  Logger - $SPLUNK_HOME/etc/log.cfg:263: Pa&lt;BR /&gt;
rse error at "appender.idata_ResourceUsage.serialization=JSON"&lt;BR /&gt;
07-12-2019 07:00:43.255 -0500 WARN  Logger - $SPLUNK_HOME/etc/log.cfg:273: Pa&lt;BR /&gt;
rse error at "appender.idata_DiskObjects.serialization=JSON"&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:18:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386918#M69406</guid>
      <dc:creator>Manilyn</dc:creator>
      <dc:date>2020-09-30T01:18:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start Splunk forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386919#M69407</link>
      <description>&lt;P&gt;You should be able to see more specific errors in &lt;STRONG&gt;&lt;EM&gt;/opt/splunk/var/log/splunk/splunkd.log&lt;/EM&gt;&lt;/STRONG&gt;.&lt;BR /&gt;
Share some of the log if you're not able to determine what the problem is.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 17:01:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386919#M69407</guid>
      <dc:creator>oscar84x</dc:creator>
      <dc:date>2019-07-12T17:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start Splunk forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386920#M69408</link>
      <description>&lt;P&gt;I resolved the issue by commenting JSON lines from log.cfg&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 17:40:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/386920#M69408</guid>
      <dc:creator>Manilyn</dc:creator>
      <dc:date>2019-07-12T17:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to start Splunk forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/654074#M110903</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190775"&gt;@Manilyn&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please let me know what all changes you performed on log.cfg?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 13:03:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Unable-to-start-Splunk-forwarder/m-p/654074#M110903</guid>
      <dc:creator>subham29</dc:creator>
      <dc:date>2023-08-11T13:03:15Z</dc:date>
    </item>
  </channel>
</rss>

