Getting Data In

switch forwarders to new indexer

rameshlpatel
Communicator

Hi,

I have existing indexer with 6.0 version and same version for all forwarders.

Now we got new splunk physical server with version 6.1.1,

Not I am switching forwarder to new server by replacing server attribute. However its not able to forward to new.

please suggest me what i have to consider before moving to new server ? Is data file will affect to due to this ? Please suggest me solution.

outputs.conf
[tcpout]
defaultGroup=DBGroup

[tcpout:DBGroup]
server =alpputl018:9997

Tags (2)
0 Karma

linu1988
Champion

First step before migrating between platform is to check the network connectivty

Ping alpputl018
telnet alpputl018 "receiving_port/9997"

new server will not be having the receiving configured. Check it right away.

Check the forwarder logs what is the issue if is not able to connect.

Thanks,
L

0 Karma

rameshlpatel
Communicator

Not played with indexes.conf in old or new server.

0 Karma

harald_leitl
Path Finder

what about indexes.conf? same config on old and new server?

0 Karma

rameshlpatel
Communicator

Yes. its opened

0 Karma

harald_leitl
Path Finder

is tcp port 9997 open on new index server?

0 Karma

rameshlpatel
Communicator

Adding more details. _internal logs are seeing in new server but not application log.

0 Karma

rameshlpatel
Communicator

IS data monitoring pointer will affect due to this ?

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...