I am attempting to install a demo of the Splunk App for VMWare (3.0.1) according to the Installation and Configuration manual and am having some trouble getting the Data Collection Node to work as documented.
I've deployed the DCN OVF, enabled forwarding via the CLI and added the DCN into the Search Head's app configuration. I don't see any of the respective inv, perf or other indexes increasing in size over several minutes. When I inspect ../var/log/splunk/hydra_worker_ta_vmware_collection_worker_alpha.log, I see the following lines appearing every few minutes:
ERROR [ta_vmware_collection_worker://alpha:1816] [getJob] job=job_887582cfa85311e3ac7e0050569571f3 has expired and will not be run.
I've tried re-deploying the DCN, though it exhibits the same behavior. Any help would be greatly appreciated.
Thanks. In my case, I think it was a problem with the time not being synced across all my Splunk instances. Yep.
Thanks. In my case, I think it was a problem with the time not being synced across all my Splunk instances. Yep.
In your case...even DataCollections Nodes are supposed to be in a time sync with rest of the Splunk Instances...??
You can increase the TTL in limits.conf and savedsearches.conf