Installation

Unable to send data to indexer

rahiparikh
Explorer

Hi,

I am trying to configure a lab environment but I am not seeing data in indexer. When I checked splunkd.log it says --

ERROR TcpOutputProc - Illegal format for config item 'uri'
ERROR NetUtils - Illegal format for config item 'uri'

My config files are stored in /opt/splunkforwarder/etc/system/local and they look like -

[inputs.conf]

[default]
host = a_web.splunk.lab.x.y.z

[monitor:///var/log/messages]
disabled = 0
followTail = 1

[monitor:///var/log/cron]
disabled = 0
followTail = 1

[monitor:///var/log/secure]
disabled = 0
followTail = 1

[monitor:///var/log/maillog]
disabled = 0
followTail = 1

[monitor:///var/log/spooler]
disabled = 0
followTail = 1

[outputs.conf]

[tcpout]
defaultGroup = splunk-lab

[tcpout:splunk-lab]
autoLB = true
server = a_indexer.splunk.lab.x.y.z:5050

[deploymentclient.conf]

[target-broker:deploymentServer]
targetUri = a_deploy.splunk.lab.x.y.z:8089

Can you give me some idea of what's going on?

0 Karma
1 Solution

Ayn
Legend

My guess without being able to validate myself - using underscores in hostnames is somewhat non-standard, so Splunk might perhaps be refusing to accept that format in the hostnames you specified.

View solution in original post

0 Karma

paranoid
Explorer

FWIW, I just had the exact same error message. It was caused by a missing port number in the server directive in outputs.conf.

Btw, it would be so much easier if splunk provided the name of the file where the error is found.

Ayn
Legend

My guess without being able to validate myself - using underscores in hostnames is somewhat non-standard, so Splunk might perhaps be refusing to accept that format in the hostnames you specified.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...