Getting Data In

Getting isHttpOutConfigured=NOT_CONFIGURED in Splunkd logs

prajwal_94
Explorer

I had defined the complete path in inputs.conf and restarted the Splunkforwarder but got error in Splunkd logs.

Kindly refer the attachment.

IMG_0870.jpegIMG_0870.jpeg

Labels (1)
0 Karma

prajwal_94
Explorer

Hi @richgalloway ,Thanks for the reply but may I know what needs to be done here so that data is forwarded to indexer and then search results are obtained.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You've already done what is necessary.  A TCP connection to the indexer(s) is all you need.

Forwarders are a one-way device.  They send data to indexers, but do not obtain search results.  Searches and their results go through a search head.

---
If this reply helps you, Karma would be appreciated.
0 Karma

prajwal_94
Explorer

Hi @richgalloway ,even TCP connection is setup to the indexer and its port. No firewall blocking as well but still no events being returned on search. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The message appears because httpout is not configured.  The outputs.conf file shown defines tcpout, not httpout.  Since the [httpout] stanza is optional, these INFO messages can be ignored.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...