Deployment Architecture

Cooked connection time out with splunk heavy forwarder

moohkhol
New Member

Hi Guys,
I know, many people have asked this question and i have gone through many post but still no clue to solve my problem.

I have set-up heavy forwarder ,
Path: /splunk/etc/system/default

inputs.conf

[monitor:///usr/local/.../test.log]
index = main
sourcetype = %sourcetype%

[splunktcp://9997]
connection_host = ip

outputs.conf

[tcpout]
defaultGroup = splunkindexer_9997

indexAndForward = 1

[tcpout:splunkindexer_9997]

autoLB = true

server = serverip:9997

[tcpout-server://serverip:9997]

Our indexer has installed on serverip and from GUI, i have added TCP input type where i have given index as main and sourcetype as sourcetype

I have restart many time and still i am getting error cooked connection and connection time out.

One interesting thing, at indexer side, if i am searching sourcetype=sourcetype I am getting cooked events from forwarder machine but actual log data are not getting forwarded.

Please suggest.

Tags (1)
0 Karma
1 Solution

Ayn
Legend

From the looks of it you've configured a raw TCP input on port 9997 on the indexer rather than a receiving port. It needs to be splunktcp, not tcp in inputs.conf. Could you please paste relevant inputs.conf on the indexer?

View solution in original post

moohkhol
New Member

Thanks a lot Ayan, it's works for me, I have change splunktcp at indexer side.

0 Karma

Ayn
Legend

No problem. Please mark my answer as accepted.

0 Karma

Ayn
Legend

From the looks of it you've configured a raw TCP input on port 9997 on the indexer rather than a receiving port. It needs to be splunktcp, not tcp in inputs.conf. Could you please paste relevant inputs.conf on the indexer?

Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...