Getting Data In

HTTP Event Collector Connection Actively Refused after upgrading from 9.0.5 to 9.1.1 (No Token Found)

C_Lawrence
Engager

Hi,

We have just upgraded to 9.1.1 and our HEC seems to have stopped working. 

Calling it from a simple PowerShell script worked the day before and running it now throws this error :

Unable to connect to the remote server
No connection could be made because the target machine actively refused it xxx.xxx.xxx.xxx:8088

So, headed over to the Forwarder where it should be listening, and the tokens do still exist in the Inputs.conf in "/opt/splunkforwarder/etc/apps/splunk_httpinput/local"

However, issuing the list command gives us the following :

$SPLUNK_HOME/bin/splunk http-event-collector list -uri https://localhost:8089

Token Not Found

The HEC is Enabled in the Global Settings but we are also not seeing anything listening on Port 8088

Splunk Enterprise on a Linux build.

Labels (2)
Tags (1)

emallinger
Communicator

Hi,

yes, that's exactly what I did and that fixed the issue in my case :).

Thanks !

Ema

0 Karma

emallinger
Communicator
0 Karma

C_Lawrence
Engager

Hi,

 

So sorry. I though I had update and resolved this message.

As I was trying to get logged in (it took a while!), you sent the other update. That was not the fix for me.

While I had a case open for while with Splunk, I cam across this fix :

On the Forwarder :

/opt/splunkforwarder/etc/system/local/server.conf

Add this Stanza :

[httpServer]
mgmtMode = tcp

 

Regards.

emallinger
Communicator

Hello,

Same symptoms here upgrading from 9.0.5 to 9.1.3...

Did you find out what was the workaround ?

What did you do ?

Thanks !

Ema

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...