<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forwarder not starting in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454817#M78711</link>
    <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;Save a copy of inputs.conf from the current instance, re-install the forwarder and place the saved copy of inputs.conf in the correct directory. &lt;/P&gt;

&lt;P&gt;I would also adjust the Ulimits to the recommended settings. &lt;/P&gt;

&lt;P&gt;Cheers,  &lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 20:06:56 GMT</pubDate>
    <dc:creator>jimmytpowers</dc:creator>
    <dc:date>2019-07-02T20:06:56Z</dc:date>
    <item>
      <title>Forwarder not starting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454816#M78710</link>
      <description>&lt;P&gt;I have forwarder down since past two months, when i brought it up it generated errors. &lt;/P&gt;

&lt;P&gt;No Splunkd logs have been created.  I understand that Ulimit is not set as per Splunk documentation but it should start at least.&lt;BR /&gt;
If someone can let me know what is the possible issue of Forwarder not starting.&lt;/P&gt;

&lt;P&gt;Checking prerequisites...&lt;BR /&gt;
WARNING: Data segment size limit (ulimit -d) is set low (134217728 bytes)  Splunk may not work.&lt;BR /&gt;
         You may want to run "ulimit -d unlimited" before starting splunk.&lt;BR /&gt;
WARNING: Resident memory size limit (ulimit -m) is set low (33554432 bytes)  Splunk may not work.&lt;BR /&gt;
         You may want to run "ulimit -m unlimited" before starting splunk.&lt;BR /&gt;
WARNING: File size limit (ulimit -f) is set low (1073741312 bytes)  Splunk may not work.&lt;BR /&gt;
         You may want to run "ulimit -f unlimited" before starting splunk.&lt;BR /&gt;
        Checking mgmt port [8089]: open&lt;BR /&gt;
&lt;STRONG&gt;Assertion failed: _linkp == nullptr, file  /home/build/build-src/orangeswirl/src/util/TimeoutHeap.cpp, line 46&lt;/STRONG&gt;&lt;BR /&gt;
Dying on signal #6 (si_code=0), sent by PID 0 (UID 0). Attempting to clean up pidfile&lt;BR /&gt;
ERROR: pid 5702028 terminated with signal 6&lt;BR /&gt;
&lt;STRONG&gt;SSL certificate generation failed&lt;/STRONG&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 13:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454816#M78710</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-07-02T13:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not starting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454817#M78711</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;

&lt;P&gt;Save a copy of inputs.conf from the current instance, re-install the forwarder and place the saved copy of inputs.conf in the correct directory. &lt;/P&gt;

&lt;P&gt;I would also adjust the Ulimits to the recommended settings. &lt;/P&gt;

&lt;P&gt;Cheers,  &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 20:06:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454817#M78711</guid>
      <dc:creator>jimmytpowers</dc:creator>
      <dc:date>2019-07-02T20:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not starting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454818#M78712</link>
      <description>&lt;P&gt;Thanks for the suggestion.  Can i install Splunk on some other directory and copy all the configurations?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 20:28:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454818#M78712</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-07-02T20:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not starting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454819#M78713</link>
      <description>&lt;P&gt;Yes, and you can delete the old forwarder directory once you apply all the old configs to the new, and get the data forwarding to indexers.  &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 21:21:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454819#M78713</guid>
      <dc:creator>jimmytpowers</dc:creator>
      <dc:date>2019-07-02T21:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not starting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454820#M78714</link>
      <description>&lt;P&gt;Thanks much i will do it and update you if it works..&lt;/P&gt;

&lt;P&gt;Meanwhile i have some doubt on server.conf of old forwarder. This forwarder was installed by someone else and it has sslPassword stanza with some values. How can we get this value or it geneartes automatically when we install forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 21:29:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454820#M78714</guid>
      <dc:creator>ramprakash</dc:creator>
      <dc:date>2019-07-02T21:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Forwarder not starting</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454821#M78715</link>
      <description>&lt;P&gt;It can generate certs by default, and they expire after 3 years.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Aboutsecuringdatafromforwarders"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Aboutsecuringdatafromforwarders&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 21:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Forwarder-not-starting/m-p/454821#M78715</guid>
      <dc:creator>jimmytpowers</dc:creator>
      <dc:date>2019-07-02T21:37:49Z</dc:date>
    </item>
  </channel>
</rss>

