Hi,
I am trying to setup forwarding on my Splunk instance and need information about the following stanza in etc/system/local/inputs.conf.
[splunktcp://9997]
connection_host = none
Appreciate your help here.
On occasion you may experience all of your forwarders dropping off-line.
The stanza you mentioned fixes the problem.
How it works, no one really knows.... Well, some folks do. Looks like a DNS issue.
http://answers.splunk.com/answers/49833/splunk-forwarder-connection-refused-from-splunk-indexer
http://answers.splunk.com/answers/43259/intermediate-forwarder-connections-timeout
On occasion you may experience all of your forwarders dropping off-line.
The stanza you mentioned fixes the problem.
How it works, no one really knows.... Well, some folks do. Looks like a DNS issue.
http://answers.splunk.com/answers/49833/splunk-forwarder-connection-refused-from-splunk-indexer
http://answers.splunk.com/answers/43259/intermediate-forwarder-connections-timeout