I have just started to implement splunk in my network. I have few servers, but I would like to start with Unix machines.
I have donwloaded and installed main server and it looks fine.
The problem starts when it goes to forwarder...
I have updated following file:
[tcpout] maxQueueSize = 500KB indexAndForward=true [tcpout:fastlane] server = 10.251.1.1:6996 sendCookedData = false
When I put command:
/opt/splunkforwarder/bin/splunk list forward-server
Active forwards: None Configured but inactive forwards: 10.251.1.1:6996
How do I enable this forward mode ??
I have also tried:
[splunk@CentOS01 splunkforwarder]$ /opt/splunkforwarder/bin/splunk enable app SplunkLightForwarder In handler 'localapps': Application does not exist: SplunkLightForwarder
Any help from you would be nice 🙂
This is iptables rules problem I solved it by running following command ;
iptables -I INPUT -p tcp -m state --state NEW -m tcp --dport 9997 -m comment --comment "splunk remote Listener" -j ACCEPT
Refer this page for more
qf@qan0030:~> /opt/splunkforwarder/bin/splunk list forward-server
Configured but inactive forwards:
I am also seeing the same problem, Please help me out how to resolve this issue.
my active forwards are none.
You're having a UniversalForwarder and want to send data to another forwarder "HeavyForwarder" right? The command
splunk list forward-servers shows you only, if the connection from UniversalForwarder to "HeavyForwarder" has been established. In this case there is no established connection - HeavyForwarder does not accept input from your UniversalForwarder!
Make sure you've setup receiving on server 10.251.1.1 (incl. listening on port 6996) correctly. While starting up your UniversalForwarder open on both (UniversalForwarder & HeavyForwarder) servers the logfiles ->
What does the log telling you?