Splunk Enterprise

Why the error after restart from a windows vm that I installed the forwarder on and I put info in the outputs.conf?

domino30
Path Finder

Capture.PNG

  This is after a restart from a windows vm that I installed the forwarder on and I put info in the outputs.conf 

outputs.conf.PNG

 this is my outputs.conf file i tried to make it the same for windows and linux

currently box 1 is linux vm and box 2 is windows vm Ihave alled traffic on 8089,9997 and so on

i can ping linux host and what I believe to be the ip of splunk.

so first question is whats that error telling me (what do I need to change)?

If my linux ifconfig comes back as 10.1.1.2

but my nslookup of httpS://dinkdonk   comes back as 10.1.10.20

which am I using as the ip for forwarding ip address 

like when I do this on either linux or windows that ip should be the same right ? see below

./splunk add forward-server 10.10.10.10:9997

./splunk set deploy-poll 10.10.10.10:8089

Also just making sure in this case my linux vm is my DS and search head and indexer right?

 

 

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...