Splunk Enterprise

What is the best way to set up ouptuts.conf in a clustered environment?

domino30
Path Finder

There a about 3 ways to set up outputs.conf and  when you trying to setup forwarders. 

you can either do a cli entry to add a forwarder server(and indexer) or you cand edit outputs .conf files

We made the outputs .conf according to a tutorial we saw but were have issues getting data in.

So the question is what is broken about our outputs.conf file 

(also side note originallt the.102 address wasnt in the files and neither was default-autolb group)

thanks

 

Screenshot 2023-02-14 131119.png

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @domino30,

The first problem I noticed is on Indexer Discovery you should use your Cluster Manager URI. It seems you put one of the indexers uri. 

Second, setting multiple output groups in tcpout causes duplicate on your indexers. Because they are the same indexers in your setup.

Please try below options;

Standart;

[tcpout]
defaultGroup = default-autolb-group
useAck = true

[tcpout: default-autolb-group]
disabled = false
server = 10.4.118.101:9997,10.4.118.102:9997

Using indexer Discovery;

[indexer discovery:master]
pass45ymmKey = $7$KrvL49XMjNER+igV1IXAr 3BVzBwe8rF2ruT/wbeD1kxD4PHc
manager_uri = https://<cluster_manager_ip>:8089

[tcpout: group1]
indexerDiscovery = master

[tcpout]
defaultGroup = group1
useAck = true

 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

Hi @domino30,

The first problem I noticed is on Indexer Discovery you should use your Cluster Manager URI. It seems you put one of the indexers uri. 

Second, setting multiple output groups in tcpout causes duplicate on your indexers. Because they are the same indexers in your setup.

Please try below options;

Standart;

[tcpout]
defaultGroup = default-autolb-group
useAck = true

[tcpout: default-autolb-group]
disabled = false
server = 10.4.118.101:9997,10.4.118.102:9997

Using indexer Discovery;

[indexer discovery:master]
pass45ymmKey = $7$KrvL49XMjNER+igV1IXAr 3BVzBwe8rF2ruT/wbeD1kxD4PHc
manager_uri = https://<cluster_manager_ip>:8089

[tcpout: group1]
indexerDiscovery = master

[tcpout]
defaultGroup = group1
useAck = true

 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

shandr
Path Finder

If you are seeing Invalid key in stanza (on start up) then check for typos

[indexer_discovery:master]
pass4SymmKey = ...

Refer to
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Outputsconf#outputs.conf.spec

0 Karma
Get Updates on the Splunk Community!

New This Month - Splunk Observability updates and improvements for faster ...

What’s New? This month, we’re delivering several enhancements across Splunk Observability Cloud for faster and ...

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...