I configured a forwarder to send data to my Splunk Cloud instance and data is not showing there. Is additional configuration required to make it work with Splunk Cloud?
I have tested with a sample log file that the forwarder works ok.
My Splunk_TA_Stream inputs.conf:
[streamfwd://streamfwd]
splunk_stream_app_location = https://input-<xxxxx>.cloud.splunk.com:9997
disabled = 0
Streamfwd.log shows:
2015-09-04 19:00:28 ERROR 0x113783000 stream.CaptureServer - Unable to ping server (66d378ba-eb52-4a95-bbef-57cb919ccfba): Unable to establish connection to input-<xxxxx>.cloud.splunk.com: sslv3 alert handshake failure
Please try using your splunk web UI port (8000?) instead of the data port (9997) for splunk_stream_app_location. It uses this to pull down configuration information via the REST API. Your splunkd forwarder will send the events from stream to port 9997 assuming it is configured properly via outputs.conf.