Installation

Unable to send data to indexer

rahiparikh
Explorer

Hi,

I am trying to configure a lab environment but I am not seeing data in indexer. When I checked splunkd.log it says --

ERROR TcpOutputProc - Illegal format for config item 'uri'
ERROR NetUtils - Illegal format for config item 'uri'

My config files are stored in /opt/splunkforwarder/etc/system/local and they look like -

[inputs.conf]

[default]
host = a_web.splunk.lab.x.y.z

[monitor:///var/log/messages]
disabled = 0
followTail = 1

[monitor:///var/log/cron]
disabled = 0
followTail = 1

[monitor:///var/log/secure]
disabled = 0
followTail = 1

[monitor:///var/log/maillog]
disabled = 0
followTail = 1

[monitor:///var/log/spooler]
disabled = 0
followTail = 1

[outputs.conf]

[tcpout]
defaultGroup = splunk-lab

[tcpout:splunk-lab]
autoLB = true
server = a_indexer.splunk.lab.x.y.z:5050

[deploymentclient.conf]

[target-broker:deploymentServer]
targetUri = a_deploy.splunk.lab.x.y.z:8089

Can you give me some idea of what's going on?

0 Karma
1 Solution

Ayn
Legend

My guess without being able to validate myself - using underscores in hostnames is somewhat non-standard, so Splunk might perhaps be refusing to accept that format in the hostnames you specified.

View solution in original post

0 Karma

paranoid
Explorer

FWIW, I just had the exact same error message. It was caused by a missing port number in the server directive in outputs.conf.

Btw, it would be so much easier if splunk provided the name of the file where the error is found.

Ayn
Legend

My guess without being able to validate myself - using underscores in hostnames is somewhat non-standard, so Splunk might perhaps be refusing to accept that format in the hostnames you specified.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...