I have used Splunk to threat hunt many times and have aspirations to build a distributed Splunk instance in the feature. I decided to start learning the installation, configuration, and deployment process of Splunk, by building a standalone instance. I get to a point where I think I have completed all the steps necessary to have a functioning Splunk set up. (connections are established on 8089 and 9997) and my web page is good. As soon as my apps are pushed to my (client) this is when Splunk starts throwing an error stating indexers and ques are full. it also appears I am getting no logs from my applications. Any help is greatly appreciated.
Hi @MorgenHepton,
could you share your error?
are you receiving Splunk internal logs?
you can check this running a simple search index=_internal host=<your_host>
what is you architecture? I understood that you have an stand-alone Splunk server (an all-in-one installation) and a Universal Forwarder (in a different system) that sgould send logs to the stand-alone system, is it correct?
running a telnet on the UF on ports 9997 and 8089 can you reach to connect the stand-alone server?
Ciao.
Giuseppe
thankyou for the reply.
The errors Im getting are all under splunkd
errors include
[tcpoutautolb-0, file monitor input, ingestion latency, real-time reader-0, and more.]
sadly I did not save my errors before I decided to delete the Splunk instances and try and reinstall.
I believe I was receiving logs in the index _internal.
My deployment looks like this
(splunk all-in- on (redhat linux))-------------------(S.U.F (rocky linux))
Hi @MorgenHepton,
did you configured your UF to send logs to te Indexer?
for more infos see at https://docs.splunk.com/Documentation/Forwarder/9.2.0/Forwarder/Configuretheuniversalforwarder
Ciao.
Giuseppe