Installation

Problems with Splunk "eventType=connect_fail"

joseluisrespeto
Explorer

Good afternoon,

How can i check that the forwarders are sending the logs correctly? I have the following error in my logs:

"eventType=connect_fail" in metrics.log

metrics.log:12-17-2014 09:38:48.529 +0100 INFO StatusMgr - destHost=10.26.XX.XX, destIp=10.26.XX.XX, destPort=9997, eventType=connect_fail, publisher=tcpout, sourcePort=8089, statusee=TcpOutputProcessor

This event produce that the los are not been sending correctly, them i need know if any option in the program execution can check if splunk is sending or not the data to the server.

And, can i resolve this issue in the configuration with some parameter? This issue only appear in determinate times isn't fixed.

Thanks and regards.

Tags (2)

joseluisrespeto
Explorer

up up up !

0 Karma

brreeves_splunk
Splunk Employee
Splunk Employee

I downvoted this post because this did not answer the question. how did you get it working?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...