Getting Data In

Why are servers connecting to my deployment server, but not the indexers?

JoeSco27
Communicator

I have created and deployed the following serverclass.conf stanza:

[serverClass:dt-exdata]
whitelist.0 = dt1exdata*
[serverClass:dt-exdata:app:dt-exdata-inputs]

and when i look on my deployment server under Settings >> Distributed environment >> Forwarder management >> I can see the clients phoneHome and the dt-exdata-inputs app being deployed to the dt1exdata servers. When i then go to my indexer i do not see any logs from those servers. I have had my network team telnet to my deployment server over port 8089 and to my indexer over port 9997 and the connections were both successful. I am not sure why i would be able to see the dt1exdata servers connecting to my deployment server but not my indexers.

We also checked one of the dt1exdata servers and the outputs.conf was pointing to the correct location and the dt-exdata-inputs app was in the apps directory.

0 Karma

chanfoli
Builder

The first place I would look in this case is in the splunkd.logs on your forwarders (SPLUNKHOME/var/log/splunk/splunkd.log) . I would look for messages about connections. I would also run SPLUNKHOME/bin/splunk list forward-server

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...