All Apps and Add-ons

streamfwd and Splunk Cloud: unable to establish connection

vlado
Engager

I configured a forwarder to send data to my Splunk Cloud instance and data is not showing there. Is additional configuration required to make it work with Splunk Cloud?

I have tested with a sample log file that the forwarder works ok.

My Splunk_TA_Stream inputs.conf:
[streamfwd://streamfwd]
splunk_stream_app_location = https://input-<xxxxx>.cloud.splunk.com:9997
disabled = 0

Streamfwd.log shows:
2015-09-04 19:00:28 ERROR 0x113783000 stream.CaptureServer - Unable to ping server (66d378ba-eb52-4a95-bbef-57cb919ccfba): Unable to establish connection to input-<xxxxx>.cloud.splunk.com: sslv3 alert handshake failure

0 Karma

mdickey_splunk
Splunk Employee
Splunk Employee

Please try using your splunk web UI port (8000?) instead of the data port (9997) for splunk_stream_app_location. It uses this to pull down configuration information via the REST API. Your splunkd forwarder will send the events from stream to port 9997 assuming it is configured properly via outputs.conf.

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...