Installation

Splunk LightForwarder Upgrade from 4.0.8 to 4.1.5 - connection problem

sebastian1
New Member

Hello together,

we have a problem with our splunk lightforwarders (MS Windows 2003). After upgrading from 4.0.8 to 4.1.5 we encountered a problem with the connection from the forwarders to our index server. There is no new data arriving while a connection between both servers (port 9997) can be verified (lsof -i -P -n | grep ). Do we need to migrate our outputs.conf or anything else?

Best regards Sebastian

0 Karma

Brian_Osburn
Builder
0 Karma

sebastian1
New Member

now we have tried several other version and it seems like the latest 4.0 version (4.0.11) works. btw. linux systems using 4.1.5 are delivering just fine. only windows systems don't deliver at all in 4.1.x

0 Karma

sebastian1
New Member

yes thats right. we only create a new outputs.conf on order to connect to the index server via ssl. everything else keeps normal. in fact we are using the same configuration on 4.0.8 and in 4.1.5.

0 Karma

Genti
Splunk Employee
Splunk Employee

If i understood this correctly you are saying that installing 4.0.8 (brand new) works, but installing 4.1.5 does not? What config files are you using, can you make sure that outputs.conf and inputs.conf have been setup correctly for the 4.1.5 version? It would be helpful to check in your splunkd.log for any errors.

0 Karma

sebastian1
New Member

currently we are trying to enable our new inputs.conf (disbales all kinds of WMI indexing) in 4.0.8 to see if the error is within our new configuration.

0 Karma

sebastian1
New Member

we cannot see something strange. btw. using the old 4.0.8 make the forwarders deliver again.

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...