Getting Data In

Sending Data to Splunk Cloud from Heavy Forwarder

ayuri
Engager

Hi,

I have an app which collects logs and I have configured it to send data to a local enterprise instance of splunk and splunk cloud, I can see the data in the local enterprise instance but not in the cloud instances

I do see the following which shows connection has been established

 

11-09-2020 10:19:08.710 +0000 INFO Metrics - group=tcpin_connections, ingest_pipe=0, 73.202.128.135:57829:9997, connectionType=cookedSSL, sourcePort=57829, sourceHost=3.202.128.13, sourceIp=3.202.128.13, destPort=9997, kb=0.326171875, _tcp_Bps=10.774122169132621, _tcp_KBps=0.010521603680793575, _tcp_avg_thruput=0.011187444180915055, _tcp_Kprocessed=10.939453125, _tcp_eps=0.03225785080578629, _process_time_ms=0, evt_misc_kBps=0, evt_raw_kBps=0, evt_fields_kBps=0, evt_fn_kBps=0, evt_fv_kBps=0, evt_fn_str_kBps=0, evt_fn_meta_dyn_kBps=0, evt_fn_meta_predef_kBps=0, evt_fn_meta_str_kBps=0, evt_fv_num_kBps=0, evt_fv_str_kBps=0, evt_fv_predef_kBps=0, evt_fv_offlen_kBps=0, evt_fv_fp_kBps=0, build=a6754d8441bf, version=8.0.3, os=Linux, arch=x86_64, hostname=splunkforwarder, guid=8ECC1FB9-30F3-4F5E-AB9A-9668E6BCCDDD, fwdType=full, ssl=true, lastIndexer=107.22.176.26:9997, ack=false

root@splunkforwarder:/home/linux# /opt/splunk/bin/splunk search 'index=_internal source=*metrics.log* destHost | dedup destHost'
Splunk username: splunk
Password:
11-09-2020 10:14:48.227 +0000 INFO StatusMgr - destHost=prd-p-f4rpr.splunkcloud.com, destIp=107.22.176.26, destPort=9997, eventType=connect_fail, publisher=tcpout, sourcePort=8089, statusee=TcpOutputProcessor
11-09-2020 10:02:51.476 +0000 INFO StatusMgr - destHost=inputs.prd-p-f4rpr.splunkcloud.com, destIp=107.22.176.26, destPort=9997, eventType=connect_done, publisher=tcpout, sourcePort=8089, statusee=TcpOutputProcessor
11-09-2020 10:02:21.773 +0000 INFO StatusMgr - destHost=192.168.5.131, destIp=192.168.5.131, destPort=9997, eventType=connect_done, publisher=tcpout, sourcePort=8089, statusee=TcpOutputProcessor
root@splunkforwarder:/home/linux#

Labels (5)
0 Karma

ayuri
Engager

I am using a heavy forwarder setup (with the app pulling and forwarding data)

0 Karma