Getting Data In

Forwarder not indexing

rcovert
Path Finder

I have one Linux indexer and 2 Linux forwarders. I just moved my indexer to a new server and have everything set up again. I changed the receiving server in both of my forwarders in /opt/splunkforwarder/etc/system/local/outputs.conf to point to the new IP address.

In the Deployment monitor app, I see both forwarders and it looks like data is coming in from both of them. But, when I look in the search app, it is not showing data coming from one of the forwarders under hosts. Any ideas?

0 Karma
1 Solution

rcovert
Path Finder

I found the answer. Grr..

I had a extra space between a ":" and the IP address of the indexer.

View solution in original post

0 Karma

rcovert
Path Finder

I found the answer. Grr..

I had a extra space between a ":" and the IP address of the indexer.

0 Karma

rcovert
Path Finder

This is being repeated in the splunkd.log on the forwarder:

06-05-2012 14:22:35.044 -0400 ERROR pipeline - Runtime exception in pipeline: parsing, processor: tcp-output-light-forwarder, error: vector::_M_range_check
06-05-2012 14:22:35.044 -0400 ERROR splunklogger - Uncaught exception in pipeline execution (tcp-output-light-forwarder) - getting next event

index="_internal" source="/Applications/Splunk/splunk/var/log/splunk/splunkd.log" shows 0 results.

0 Karma

sdaniels
Splunk Employee
Splunk Employee

Are you seeing anything in your splunkd log?
/var/log/splunk

or in the UI via this search

index="_internal" source="/Applications/Splunk/splunk/var/log/splunk/splunkd.log"

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...