Splunk Enterprise

Can't see list of Forwarders on Search Head?

Gregski11
Contributor

despite having a local\outputs.conf file properly populated with 6 Indexers one of our non clustered Search Heads does not show anything under Forward data as defined in the Web GUI

any suggestions where and how to check what is over writing this 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The outputs.conf file tells a Splunk instance where to send its data.  It does NOT tell a SH what or where any forwarders are. 

You can use the Monitoring Console to see your forwarders, but you'll have to enable Forwarder Monitoring first in the Settings menu.

---
If this reply helps you, Karma would be appreciated.

Gregski11
Contributor

Hi Rich, sorry about that poor choice of words on my part, though Splunk does make it a bit confusing in the Web UI, so it's under Settings \ [DATA] Forwarding and receiving and then under the Forward data section you click on Configure forwarding

 

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The Configure Forwarding page is where one tells that Splunk instance (SH, in this case) where to forward data.  It's an alternative to editing an outputs.conf file on that server.  The page has no bearing on your heavy or universal forwarders.

There is the Settings->Forwarder Management page for managing forwarders, but that should only be used on your Deployment Server.

What problem are you trying to solve?

---
If this reply helps you, Karma would be appreciated.

Gregski11
Contributor

one of our Search Heads though it has a local\outputs.conf file with 6 Indexers listed in it, does NOT show any listed on the Forwarding and receiving Web UI page, like all our other Search Heads and I can't figure out why that is 

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Try to run btool in your user's context to see if the outputs setting is visible.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Interesting.  I don't know why that would be.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...