Deployment Architecture

Cooked connection time out with splunk heavy forwarder

moohkhol
New Member

Hi Guys,
I know, many people have asked this question and i have gone through many post but still no clue to solve my problem.

I have set-up heavy forwarder ,
Path: /splunk/etc/system/default

inputs.conf

[monitor:///usr/local/.../test.log]
index = main
sourcetype = %sourcetype%

[splunktcp://9997]
connection_host = ip

outputs.conf

[tcpout]
defaultGroup = splunkindexer_9997

indexAndForward = 1

[tcpout:splunkindexer_9997]

autoLB = true

server = serverip:9997

[tcpout-server://serverip:9997]

Our indexer has installed on serverip and from GUI, i have added TCP input type where i have given index as main and sourcetype as sourcetype

I have restart many time and still i am getting error cooked connection and connection time out.

One interesting thing, at indexer side, if i am searching sourcetype=sourcetype I am getting cooked events from forwarder machine but actual log data are not getting forwarded.

Please suggest.

Tags (1)
0 Karma
1 Solution

Ayn
Legend

From the looks of it you've configured a raw TCP input on port 9997 on the indexer rather than a receiving port. It needs to be splunktcp, not tcp in inputs.conf. Could you please paste relevant inputs.conf on the indexer?

View solution in original post

moohkhol
New Member

Thanks a lot Ayan, it's works for me, I have change splunktcp at indexer side.

0 Karma

Ayn
Legend

No problem. Please mark my answer as accepted.

0 Karma

Ayn
Legend

From the looks of it you've configured a raw TCP input on port 9997 on the indexer rather than a receiving port. It needs to be splunktcp, not tcp in inputs.conf. Could you please paste relevant inputs.conf on the indexer?

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...