Yesterday I had set up 8 Universal Forwarders on 8 different machines and had them all sending data over to the Receiver just fine. I woke up this morning and got on the receiver and all 8 machines w...
...when the heavy forwarder trying to forward the logs to syslog server
WARN TcpOutputProc - Cooked connection to ip=syslog_ip:syslog_port timed out
ERROR TcpOutputFd - Connection to host=s...
...- Also, on the not-working system and the heavy forwarder I've run NETSTAT -an to verify that the 2 systems are establishing a connection between each other.
3 - I've dug through the var/logs/s...
I have installed a universal forwarder in one laptop and Splunk Enterprise in other laptop in my home. Both are connected via ethernet LAN. I am able to share files and folders between those l...
I am getting a TcpOutputFd on the forwarder. Connection to xxx host failed.
4-22-2015 16:17:34.736 -0400 WARN TcpOutputFd - Connect to :9997 failed. Connection refused
04-22-2015 16:17:34.745...
This question is simply out of curiosity.
If a Splunk forwarder loses its connection with its receiver (assuming there is only one receiver/no load balancing), does it hang on to the data it's s...
one of my team has installed the forwarder on a Windows client. running tcpdump on the backend of splunk enterprise shows:
08:32:06.990056 IP xxx.56097 > splunk.xxx.9997: Flags [P.], seq 777:8...
...ead logs from syslog's log folder.
network connection established between Syslog Server and H.F on H.F's port 9997 and 8089.
receiving port 9997 on Indexer enabled.
splunk btool inputs list m...
Hey,
Just wondered if anyone has seen this issue in their environment?
I noticed, by chance, that our license usage was particularly low for the day so far. I soon found that most of the forwarder...