Splunk Search

Connectivity Search

troyredskins
New Member

I have an issue with the connectivity between the heavy forwarder and the deployment server. What is a search that I could use in the GUI to diagnose the issue?

0 Karma

SanjayReddy
SplunkTrust
SplunkTrust

hi @troyredskins 

as a first check please verify connectity between HF---->DS by doing telnet from HF to deplotment server using following command.
if it is related to connectivity issue , it can resloved by enabling firewall between HF and DS. 

command: telnet deplotmentserverip:portnumber  (by default splunkd port number is 8089 but verify in deplotment server using (ps -ef | grep -i splunkd) )

example:  telnet 127.0.0.1 8089 

also verify deplotmentclient configuration on HF using command 

$SPLUNK_HOME/bin/splunk show deploy-poll 


if connecection is happening between HF and DS and as mentioned by @richgalloway 
please search for DeploymentClient  in splunkd.log on HF under  $SPLUNK_HOME/var/log/splunk to check for WARN and ERROR messages. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Look at splunkd.log on the DS and HF.  They should explain the problem.  Depending on the nature of the issue, you may have to sign in to the HF to access the log.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...