Deployment Architecture

pipelineInputChannel - ended without a done key

sdevadas
Path Finder

I keep getting these in the logs for a particular client where we have setup a scripted input which delivers the data through the light forwarder.

11-03-2010 16:13:24.763 WARN  PipelineInputChannel - channel "source::tcp:9903|host::PRDBNN301||remoteport::52186" ended without a done-key
11-03-2010 16:13:24.763 WARN  PipelineInputChannel - channel "source::s2s|host::PRDBNN301|s2s|remoteport::52186" ended without a done-key
11-03-2010 16:13:24.763 WARN  PipelineInputChannel - channel "source::wmi|host::PRDBNN301|wmi|remoteport::52186" ended without a done-key

The data from this client does not seem to reach the indexer (at least I cant search for it). This seems to work well in development.

Any pointers would be appreciated.

Splunk 4.1.5 Windows 2003 R2

Tags (1)

Lowell
Super Champion

sdevadas
Path Finder

I changed from the light forwarder to the heavy one and things work well.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...