Getting Data In

HTTP Event Collector Connection Actively Refused after upgrading from 9.0.5 to 9.1.1 (No Token Found)

C_Lawrence
Engager

Hi,

We have just upgraded to 9.1.1 and our HEC seems to have stopped working. 

Calling it from a simple PowerShell script worked the day before and running it now throws this error :

Unable to connect to the remote server
No connection could be made because the target machine actively refused it xxx.xxx.xxx.xxx:8088

So, headed over to the Forwarder where it should be listening, and the tokens do still exist in the Inputs.conf in "/opt/splunkforwarder/etc/apps/splunk_httpinput/local"

However, issuing the list command gives us the following :

$SPLUNK_HOME/bin/splunk http-event-collector list -uri https://localhost:8089

Token Not Found

The HEC is Enabled in the Global Settings but we are also not seeing anything listening on Port 8088

Splunk Enterprise on a Linux build.

Labels (2)
Tags (1)

emallinger
Communicator

Hi,

yes, that's exactly what I did and that fixed the issue in my case :).

Thanks !

Ema

0 Karma

emallinger
Communicator
0 Karma

C_Lawrence
Engager

Hi,

 

So sorry. I though I had update and resolved this message.

As I was trying to get logged in (it took a while!), you sent the other update. That was not the fix for me.

While I had a case open for while with Splunk, I cam across this fix :

On the Forwarder :

/opt/splunkforwarder/etc/system/local/server.conf

Add this Stanza :

[httpServer]
mgmtMode = tcp

 

Regards.

emallinger
Communicator

Hello,

Same symptoms here upgrading from 9.0.5 to 9.1.3...

Did you find out what was the workaround ?

What did you do ?

Thanks !

Ema

0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...