Yesterday I had set up 8 Universal Forwarders on 8 different machines and had them all sending data over to the Receiver just fine. I woke up this morning and got on the receiver and all 8 machines w...
...when the heavy forwarder trying to forward the logs to syslog server
WARN TcpOutputProc - Cooked connection to ip=syslog_ip:syslog_port timed out
ERROR TcpOutputFd - Connection to host=s...
...- Also, on the not-working system and the heavy forwarder I've run NETSTAT -an to verify that the 2 systems are establishing a connection between each other.
3 - I've dug through the var/logs/s...
I have installed a universal forwarder in one laptop and Splunk Enterprise in other laptop in my home. Both are connected via ethernet LAN. I am able to share files and folders between those l...
Hi
We have installed Splunk universal forwarder on a remote server but logs are not getting forwarded to Indexer.
I have tried to troubleshoot this issue but could not do so. Can y...
...ead logs from syslog's log folder.
network connection established between Syslog Server and H.F on H.F's port 9997 and 8089.
receiving port 9997 on Indexer enabled.
splunk btool inputs list m...
I am getting a TcpOutputFd on the forwarder. Connection to xxx host failed.
4-22-2015 16:17:34.736 -0400 WARN TcpOutputFd - Connect to :9997 failed. Connection refused
04-22-2015 16:17:34.745...
This question is simply out of curiosity.
If a Splunk forwarder loses its connection with its receiver (assuming there is only one receiver/no load balancing), does it hang on to the data it's s...
...nswers, but I haven't found one that pertain to both. It obvious in the error log on the forwarder that the connection is refused however I can telnet to the port 9997. What am I missing? This was all w...