Splunk Enterprise

What is the best way to set up ouptuts.conf in a clustered environment?

domino30
Path Finder

There a about 3 ways to set up outputs.conf and  when you trying to setup forwarders. 

you can either do a cli entry to add a forwarder server(and indexer) or you cand edit outputs .conf files

We made the outputs .conf according to a tutorial we saw but were have issues getting data in.

So the question is what is broken about our outputs.conf file 

(also side note originallt the.102 address wasnt in the files and neither was default-autolb group)

thanks

 

Screenshot 2023-02-14 131119.png

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @domino30,

The first problem I noticed is on Indexer Discovery you should use your Cluster Manager URI. It seems you put one of the indexers uri. 

Second, setting multiple output groups in tcpout causes duplicate on your indexers. Because they are the same indexers in your setup.

Please try below options;

Standart;

[tcpout]
defaultGroup = default-autolb-group
useAck = true

[tcpout: default-autolb-group]
disabled = false
server = 10.4.118.101:9997,10.4.118.102:9997

Using indexer Discovery;

[indexer discovery:master]
pass45ymmKey = $7$KrvL49XMjNER+igV1IXAr 3BVzBwe8rF2ruT/wbeD1kxD4PHc
manager_uri = https://<cluster_manager_ip>:8089

[tcpout: group1]
indexerDiscovery = master

[tcpout]
defaultGroup = group1
useAck = true

 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

Hi @domino30,

The first problem I noticed is on Indexer Discovery you should use your Cluster Manager URI. It seems you put one of the indexers uri. 

Second, setting multiple output groups in tcpout causes duplicate on your indexers. Because they are the same indexers in your setup.

Please try below options;

Standart;

[tcpout]
defaultGroup = default-autolb-group
useAck = true

[tcpout: default-autolb-group]
disabled = false
server = 10.4.118.101:9997,10.4.118.102:9997

Using indexer Discovery;

[indexer discovery:master]
pass45ymmKey = $7$KrvL49XMjNER+igV1IXAr 3BVzBwe8rF2ruT/wbeD1kxD4PHc
manager_uri = https://<cluster_manager_ip>:8089

[tcpout: group1]
indexerDiscovery = master

[tcpout]
defaultGroup = group1
useAck = true

 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...