Splunk Enterprise

Configured but inactive forwards: from Splunk list forward-server- How to activate them?

Path Finder


Please help - 

my centos 8 server is show some inactive forwards to my indexer.

[splunk@centos8 ~]$ /opt/splunkforwarder/bin/splunk list forward-server
Active forwards:
Configured but inactive forwards:
[splunk@centos8 ~]$

[tcpout] defaultGroup = default-autolb-group [tcpout:default-autolb-group] disabled = false server = mysplunkindexer1:9997,mysplunkindexer2:9997
Labels (1)
0 Karma


Verify all three indexers are up and accessible (firewalls, etc.).

Check the forwarder's splunkd.log for messages that might explain why the connections failed.

If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...