Getting Data In

Why are Linux Forwarders not talking to Deployment Server?

jordanperks
Path Finder

I have a lab setup in VMWare Workstation that has both Linux and Windows servers setup to talk to a Linux deployment server on port 8089 (default). The windows servers are talking to the deployment server, but the linux forwarders (both heavy and universal) are not. Thw windows servers are showing up in settings > forwarder management. Both windows and linux forwarders have the same configuration in deploymentclient.conf:

[target-broker:deploymentServer]
targetUri = 192.168.199.177:8089

I can ping with no problem. I have completely turned off iptables on I have gone through every log file I can find in /opt/splunk/var/log/splunk/* and cannot find any issues. Does anyone know which log I should be looking at to find the issue? I am thinking I may be having a VMWare issue since I have set this up in production many times without issue.

Labels (2)
Tags (2)
1 Solution

jordanperks
Path Finder

Well, I have found the solution. Had to set the hostname in /etc/sysconfig/network and then reboot the server.

View solution in original post

samsplunks
Explorer

If the hostname of your computer is "localhost", it won't even try to connect to the Deployment Server.

0 Karma

jordanperks
Path Finder

Well, I have found the solution. Had to set the hostname in /etc/sysconfig/network and then reboot the server.

muscafe
Explorer

Hello,
i have a similaire problem , what is the hostname to add on /etc/sysconfig/network please?
thank u for your answer

anwarmian
Communicator

Is that a forwarder on the syslog server?

0 Karma

mmukherjee
Explorer

Can you please give a more detailed description of the fix. I think I have the same issue as posted above and I could not find this path "/etc/sysconfig/network".

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Any logs relating to DeploymentClient should be in splunkd.log.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...