I'm still trying to make it work. In my forwarder log files, when my log files are modified, i have errors that appears in my forwarder log file :
01-04-2012 22:00:21.880 +0100 WARN TcpOutputFd - Connect to x.x.x.x:9997 failed. No connection could be made because the target machine actively refused it.
01-04-2012 22:00:37.521 +0100 ERROR TcpOutputFd - Connection to host=x.x.x.x:9997 failed
01-04-2012 22:03:06.650 +0100 INFO TcpOutputProc - Connected to idx=x.x.x.x:9997
Connections are allowed on port 9997, that's why i don't understand why he can't communicate with my Splunk Server.
Anyone have an idea ?
... View more