Deployment Architecture

Linux log formatting

rriley
New Member

Can't seem to get Splunk to interpret the RHEL syslog data.
I have tried several different formats:
syslog
linux_syslog_messages
Still only get this:

--splunk-cooked-mode-v3--\x00/x00... forever

Any ideas on this?

I am formatting the forwarding server the same as the indexer.

Tags (1)
0 Karma

Ayn
Legend

Your forwarder is sending Splunk cooked data to the indexer, but the port you've configured to the indexer is a regular raw TCP input, not an input for receiving cooked data. You need to remove the TCP input (Manager » Data inputs » TCP) and instead configure a Splunk receiver (Manager » Forwarding and receiving » Receive data) on the same port.

0 Karma

rriley
New Member

forwarder inputs.conf

host=myhost
[monitor:///var/log/messages]
followTail=0
disabled=false
sourcetype=syslog

forwarder outputs.conf

[tcpout]
defaultGroup=myhost_9997
server=myhost
[tcpout:myhost_9997]
autoLB=true
server=myhost:9997

for some reason there is nothing but the server name in the /local/inputs.conf file (odd). I am printing what i see in the manager gui. I have re-statted splunk...

indexer

inputs tcp 9997
Source - accept connections from all hosts yes
no source name override
sourcetype manual syslog

0 Karma

Ayn
Legend

Give us details on the setup. From what you pasted it sounds like you've setup a TCP listener on the indexer but you're forwarding splunktcp data from a Splunk forwarder.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...