<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SplunkEnterprise in Installation</title>
    <link>https://community.splunk.com/t5/Installation/SplunkEnterprise/m-p/658261#M13260</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After some days the Splunk server stop receiving input.&amp;nbsp; The forwarders are not changed, but I did some changes on splunk server (can't remember what I did).&amp;nbsp; Also know that the firewall does not cause of the problem. On server Splunk server we have also configured Splunk Uniiversal forwarder. So same server include both Splunk Enterprise + Splunk Universal forwarder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure, but I think it's some trouble with indexer since they cannot receive inputs. Have also&amp;nbsp; verified that environment variables is ok.&amp;nbsp; Also changed file permission on all filres/directories below Splunk_HOME.&amp;nbsp; &amp;nbsp;So it should be fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Splunk Universal clients (on clients),&amp;nbsp; splunkd.log says that TcpOutProc is connected to Splunk Server. It also says that the Splunk server LISTEN to *:9997.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; ss -tnlup&lt;/P&gt;&lt;P&gt;tcp LISTEN 0 128 *:9997&amp;nbsp; *:* users(("splunkd",pid=170257,fd=41))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assume telemytry data is sent to Splunkserver, but they are not indexed. One more information:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Splunk server: Settings - Data - Indexes&amp;nbsp; I can see that&amp;nbsp;&lt;/P&gt;&lt;P&gt;_audit SplunkLighForwarder $SPLUNK_DB/audit/db status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;_internal&amp;nbsp;SplunkLighForwarder $SPLUNK_DB/_internal/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;_introspection&amp;nbsp;SplunkLighForwarder $SPLUNK_DB/_introspection/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;_telemetry&amp;nbsp; SplunkLighForwarder SPLUNK_DB/_telemetry/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;history&amp;nbsp;SplunkLighForwarder&amp;nbsp;SPLUNK_DB/history/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;main&amp;nbsp;&amp;nbsp;SplunkLighForwarder&amp;nbsp;PLUNK_DB/history /default/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assume it has something to do with wrong settings on Splunk server.&amp;nbsp; Hope soemone out there can give me some usefull tips/hints. So we can use splunk again as normal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Geir J. H&lt;/P&gt;</description>
    <pubDate>Thu, 21 Sep 2023 10:56:43 GMT</pubDate>
    <dc:creator>gjhaaland</dc:creator>
    <dc:date>2023-09-21T10:56:43Z</dc:date>
    <item>
      <title>SplunkEnterprise</title>
      <link>https://community.splunk.com/t5/Installation/SplunkEnterprise/m-p/658261#M13260</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;After some days the Splunk server stop receiving input.&amp;nbsp; The forwarders are not changed, but I did some changes on splunk server (can't remember what I did).&amp;nbsp; Also know that the firewall does not cause of the problem. On server Splunk server we have also configured Splunk Uniiversal forwarder. So same server include both Splunk Enterprise + Splunk Universal forwarder.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure, but I think it's some trouble with indexer since they cannot receive inputs. Have also&amp;nbsp; verified that environment variables is ok.&amp;nbsp; Also changed file permission on all filres/directories below Splunk_HOME.&amp;nbsp; &amp;nbsp;So it should be fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Splunk Universal clients (on clients),&amp;nbsp; splunkd.log says that TcpOutProc is connected to Splunk Server. It also says that the Splunk server LISTEN to *:9997.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; ss -tnlup&lt;/P&gt;&lt;P&gt;tcp LISTEN 0 128 *:9997&amp;nbsp; *:* users(("splunkd",pid=170257,fd=41))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assume telemytry data is sent to Splunkserver, but they are not indexed. One more information:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Splunk server: Settings - Data - Indexes&amp;nbsp; I can see that&amp;nbsp;&lt;/P&gt;&lt;P&gt;_audit SplunkLighForwarder $SPLUNK_DB/audit/db status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;_internal&amp;nbsp;SplunkLighForwarder $SPLUNK_DB/_internal/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;_introspection&amp;nbsp;SplunkLighForwarder $SPLUNK_DB/_introspection/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;_telemetry&amp;nbsp; SplunkLighForwarder SPLUNK_DB/_telemetry/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;history&amp;nbsp;SplunkLighForwarder&amp;nbsp;SPLUNK_DB/history/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;main&amp;nbsp;&amp;nbsp;SplunkLighForwarder&amp;nbsp;PLUNK_DB/history /default/db&amp;nbsp;status says&amp;nbsp; disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assume it has something to do with wrong settings on Splunk server.&amp;nbsp; Hope soemone out there can give me some usefull tips/hints. So we can use splunk again as normal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Geir J. H&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2023 10:56:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/SplunkEnterprise/m-p/658261#M13260</guid>
      <dc:creator>gjhaaland</dc:creator>
      <dc:date>2023-09-21T10:56:43Z</dc:date>
    </item>
  </channel>
</rss>

