Getting Data In
Highlighted

Need help for forwarding data to indexer: configuration monitor

Path Finder

I am trying to forward only CPU/Memory load log to the indexer. Here is what I've done so far:

  1. Installed indexer(just an instance of splunk) to the server (host)
  2. Added 9997 under Settings > Receiving and forwarding > receiving configuration
  3. Installed splunkforwarder to my local machine
  4. Added hostname(server's hostname):9997 under Settings > Receiving and forwarding > forwarding configuration
  5. Installed apps for *nix to both of machines

Here's my question:

  1. How can I check the forwarder actually sends data to indexer?
  2. How can I check the indexer actually receives data from forwarder? (I checked /opt/~ … ~/splunk list forward-server at the local machine's cmd, but getting nothing)
  3. How can I limit kinds of file (data) forwarded to indexer (in order to send only CPU/Memory load)?

I will appreciate if someone gives me step by step instruction to configure settings:

+)
I am seeing the error message says like the following from forwarder's web UI

! Tcp outout pipeline blocked. Attempt '18600'to insert data failed
! skipped indexing of internal audit even will keep dropping events until indexer congestion is remedied.

Are theses related to the connection between indexer and forwarder?

0 Karma
Highlighted

Re: Need help for forwarding data to indexer: configuration monitor

Champion

Install the deployment monitor app from here:

http://apps.splunk.com/app/1294/

more over you can know from host=* command will give you the number of hosts which forwarded the data. Restart the indexer if the issue persists, happens due to busy splunkd or network blockages.

Thanks

View solution in original post

Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.