Getting Data In

indexer configured but inactive on new Linux servers

prathyusha_99
Engager

I have been working on configuring splunk on the new Linux servers that were added to our environment. I ran into some issues and would appreciate if you can help me with these. The splunk server installed in our environment is version 4.1.3. I have installed splunkforwarder-6.1 on the linux server and configured it to forward to the indexer. When I list the forward servers, It shows the indexer as configured but inactive. I have checked all the input.conf and output.conf files on the forwarder. Is this any issue of incompatibility between splunk 4.1 and splunkforwarder-6.1?
What is the best way to make this work ? update my indexer?

linu1988
Champion

prathyusha_99
Engager

Sorry, typo its inputs.conf

From the metrics log it looks like its trying and failing. I don't see any erroe message why is it failing.

06-18-2014 13:11:01.595 -0400 INFO StatusMgr - destHost=XXXXX, destIp=XXXX, destPort=9997, eventType=connect_try, publisher=tcpout, sourcePort=8089, statusee=TcpOutputProcessor
06-18-2014 13:11:08.452 -0400 INFO StatusMgr - destHost=XXXX, destIp=XXXX, destPort=9997, eventType=connect_fail, publisher=tcpout, sourcePort=8089, statusee=TcpOutputProcessor

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...