The log
07-22-2011 15:04:38.694 +1000 INFO TcpOutputProc - Connection to 172.16.40.116:9997 closed. Connection closed by server.
07-22-2011 15:04:38.694 +1000 INFO TcpOutputProc - Connection to 172.16.40.116:9997 closed. Connection closed by server.
07-22-2011 15:04:41.693 +1000 INFO TcpOutputProc - Connected to idx=172.16.40.116:9997
07-22-2011 15:04:41.694 +1000 INFO TcpOutputProc - Connected to idx=172.16.40.116:9997
07-22-2011 15:04:41.694 +1000 INFO TcpOutputProc - Connection to 172.16.40.116:9997 closed. Connection closed by server.
07-22-2011 15:04:41.694 +1000 INFO TcpOutputProc - Connected to idx=172.16.40.116:9997
07-22-2011 15:04:41.694 +1000 INFO TcpOutputProc - Connection to 172.16.40.116:9997 closed. Connection closed by server.
07-22-2011 15:04:41.694 +1000 INFO TcpOutputProc - Connection to 172.16.40.116:9997 closed. Connection closed by server.
...
Not sure how to get over it.
cat /opt/splunkforwarder/etc/system/default/outputs.conf
[tcpout]
server = 172.16.40.116:9997
disabled = false
compressed = true
cat /opt/splunkforwarder/etc/system/default/inputs.conf
...
[monitor:///var/log/messages]
disabled = false
index = _internal
sourcetype = linux_messages_syslog
Server does not receive anything.
Really appreciate help on this
Thanks!
Dimitry
... View more