Hi 722624,
I don't know other tests, the only one is to check again hostname on forwarder, are you sure that it's correct? could it be the same of another forwarder.
to debug your configuration, try to run on forwarder command
/opt/splunk/bin/splunk cmd btool output list --debug
eventually forwarding output in a text file to see if there is a misconfiguration or other configurations that you don't know.
Watching you inputs.conf I saw an error: on *nix forwarders, in the first row you have to insert three slashes (/) and not two.
in addition, why in your inputs.conf you use _TCP_ROUTING = rh_det if you have only one indexer in your outputs.conf?
Bye.
Giuseppe
... View more