Hi,
I am trying to configure a lab environment but I am not seeing data in indexer. When I checked splunkd.log it says --
ERROR TcpOutputProc - Illegal format for config item 'uri'
ERROR NetUtils - Illegal format for config item 'uri'
My config files are stored in /opt/splunkforwarder/etc/system/local and they look like -
[inputs.conf]
[default]
host = a_web.splunk.lab.x.y.z
[monitor:///var/log/messages]
disabled = 0
followTail = 1
[monitor:///var/log/cron]
disabled = 0
followTail = 1
[monitor:///var/log/secure]
disabled = 0
followTail = 1
[monitor:///var/log/maillog]
disabled = 0
followTail = 1
[monitor:///var/log/spooler]
disabled = 0
followTail = 1
[outputs.conf]
[tcpout]
defaultGroup = splunk-lab
[tcpout:splunk-lab]
autoLB = true
server = a_indexer.splunk.lab.x.y.z:5050
[deploymentclient.conf]
[target-broker:deploymentServer]
targetUri = a_deploy.splunk.lab.x.y.z:8089
Can you give me some idea of what's going on?
My guess without being able to validate myself - using underscores in hostnames is somewhat non-standard, so Splunk might perhaps be refusing to accept that format in the hostnames you specified.
FWIW, I just had the exact same error message. It was caused by a missing port number in the server directive in outputs.conf.
Btw, it would be so much easier if splunk provided the name of the file where the error is found.
My guess without being able to validate myself - using underscores in hostnames is somewhat non-standard, so Splunk might perhaps be refusing to accept that format in the hostnames you specified.