Splunk Enterprise

What is the best way to set up ouptuts.conf in a clustered environment?

domino30
Path Finder

There a about 3 ways to set up outputs.conf and  when you trying to setup forwarders. 

you can either do a cli entry to add a forwarder server(and indexer) or you cand edit outputs .conf files

We made the outputs .conf according to a tutorial we saw but were have issues getting data in.

So the question is what is broken about our outputs.conf file 

(also side note originallt the.102 address wasnt in the files and neither was default-autolb group)

thanks

 

Screenshot 2023-02-14 131119.png

Labels (1)
0 Karma
1 Solution

scelikok
SplunkTrust
SplunkTrust

Hi @domino30,

The first problem I noticed is on Indexer Discovery you should use your Cluster Manager URI. It seems you put one of the indexers uri. 

Second, setting multiple output groups in tcpout causes duplicate on your indexers. Because they are the same indexers in your setup.

Please try below options;

Standart;

[tcpout]
defaultGroup = default-autolb-group
useAck = true

[tcpout: default-autolb-group]
disabled = false
server = 10.4.118.101:9997,10.4.118.102:9997

Using indexer Discovery;

[indexer discovery:master]
pass45ymmKey = $7$KrvL49XMjNER+igV1IXAr 3BVzBwe8rF2ruT/wbeD1kxD4PHc
manager_uri = https://<cluster_manager_ip>:8089

[tcpout: group1]
indexerDiscovery = master

[tcpout]
defaultGroup = group1
useAck = true

 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

View solution in original post

scelikok
SplunkTrust
SplunkTrust

Hi @domino30,

The first problem I noticed is on Indexer Discovery you should use your Cluster Manager URI. It seems you put one of the indexers uri. 

Second, setting multiple output groups in tcpout causes duplicate on your indexers. Because they are the same indexers in your setup.

Please try below options;

Standart;

[tcpout]
defaultGroup = default-autolb-group
useAck = true

[tcpout: default-autolb-group]
disabled = false
server = 10.4.118.101:9997,10.4.118.102:9997

Using indexer Discovery;

[indexer discovery:master]
pass45ymmKey = $7$KrvL49XMjNER+igV1IXAr 3BVzBwe8rF2ruT/wbeD1kxD4PHc
manager_uri = https://<cluster_manager_ip>:8089

[tcpout: group1]
indexerDiscovery = master

[tcpout]
defaultGroup = group1
useAck = true

 

 

If this reply helps you an upvote and "Accept as Solution" is appreciated.

shandr
Path Finder

If you are seeing Invalid key in stanza (on start up) then check for typos

[indexer_discovery:master]
pass4SymmKey = ...

Refer to
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Outputsconf#outputs.conf.spec

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...