Getting Data In

A splunktcp forwarder port is not configured in inputs.conf

a212830
Champion

Hi,

I installed a heavy-forwarder, and will be monitoring some logfiles. I configured the inputs/outputs/props conf file and I restarted the forwarder, and it keeps telling me that "A splunktcp forwarder port is not configured in inputs.conf". I'm not looking to monitor any ports - why is it telling me that?

Tags (1)

mukherjee_mk
Explorer

I see the same issue too. Is it something particular to Splunk 5?

0 Karma

Ricapar
Communicator

I'm seeing the same message in my Universal Forwarder's log files as well.
This forwarder is only supposed to be reading local log files - not receiving events from any ports.

For now I'm ignoring the message.. but I'm still curious as to why it is showing up.

0 Karma

Damien_Dallimor
Ultra Champion

splunktcp is used by your receivers (indexers) that your forwarder is sending data to.
In your forwarder's outputs.conf , is the receiver host that you have specified correctly setup and listening on the splunktcp port ?

Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...