I installed splunk forwarder on a Windows Server 2008r2 server and it is failing to forward logs. The splunkd.log from the forwarder. It has a repeating error about a pipeline exception:
08-30-2012 12:54:29.309 -0600 ERROR pipeline - Runtime exception in pipeline: parsing, processor: tcp-output-light-forwarder, error: invalid vector
08-30-2012 12:54:29.309 -0600 ERROR splunklogger - Uncaught exception in pipeline execution (tcp-output-light-forwarder) - getting next event
08-30-2012 12:54:29.309 -0600 ERROR pipeline - Runtime exception in pipeline: parsing, processor: tcp-output-light-forwarder, error: invalid vector
The splunk version is 4.3.
Turns out that there is a typo in the outputs.conf:
[tcpout]
defaultGroup=dc2splunk02
[tcpout:dc2splunk01]
server=dc2splunk02:9997
Notice "[tcpout:dc2splunk01]". it should be "[tcpout:dc2splunk02]"
Correct outputs.conf stanza should be:
[tcpout]
defaultGroup=dc2splunk02
[tcpout:dc2splunk02]
server=dc2splunk02:9997
The splunk version is 4.3.
Turns out that there is a typo in the outputs.conf:
[tcpout]
defaultGroup=dc2splunk02
[tcpout:dc2splunk01]
server=dc2splunk02:9997
Notice "[tcpout:dc2splunk01]". it should be "[tcpout:dc2splunk02]"
Correct outputs.conf stanza should be:
[tcpout]
defaultGroup=dc2splunk02
[tcpout:dc2splunk02]
server=dc2splunk02:9997
which version of Splunk? i am not sure what is your issue but I would try to install a universal forwarder and make sure it has full control on the splunkforwarder folder