Getting Data In

Why are servers connecting to my deployment server, but not the indexers?


I have created and deployed the following serverclass.conf stanza:

whitelist.0 = dt1exdata*

and when i look on my deployment server under Settings >> Distributed environment >> Forwarder management >> I can see the clients phoneHome and the dt-exdata-inputs app being deployed to the dt1exdata servers. When i then go to my indexer i do not see any logs from those servers. I have had my network team telnet to my deployment server over port 8089 and to my indexer over port 9997 and the connections were both successful. I am not sure why i would be able to see the dt1exdata servers connecting to my deployment server but not my indexers.

We also checked one of the dt1exdata servers and the outputs.conf was pointing to the correct location and the dt-exdata-inputs app was in the apps directory.

0 Karma


The first place I would look in this case is in the splunkd.logs on your forwarders (SPLUNKHOME/var/log/splunk/splunkd.log) . I would look for messages about connections. I would also run SPLUNKHOME/bin/splunk list forward-server

Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...