Splunk Enterprise

Configured but inactive forwards: from Splunk list forward-server- How to activate them?

jcorcoran508
Path Finder

 

Please help - 

my centos 8 server is show some inactive forwards to my indexer.


[splunk@centos8 ~]$ /opt/splunkforwarder/bin/splunk list forward-server
Active forwards:
10.0.0.42:9997
Configured but inactive forwards:
10.0.0.36:9997
10.0.0.45:9997
[splunk@centos8 ~]$

outputs.conf
[tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] disabled = false server = mysplunkindexer1:9997,mysplunkindexer2:9997
Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Verify all three indexers are up and accessible (firewalls, etc.).

Check the forwarder's splunkd.log for messages that might explain why the connections failed.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...