All Apps and Add-ons

streamfwd and Splunk Cloud: unable to establish connection

vlado
Engager

I configured a forwarder to send data to my Splunk Cloud instance and data is not showing there. Is additional configuration required to make it work with Splunk Cloud?

I have tested with a sample log file that the forwarder works ok.

My Splunk_TA_Stream inputs.conf:
[streamfwd://streamfwd]
splunk_stream_app_location = https://input-<xxxxx>.cloud.splunk.com:9997
disabled = 0

Streamfwd.log shows:
2015-09-04 19:00:28 ERROR 0x113783000 stream.CaptureServer - Unable to ping server (66d378ba-eb52-4a95-bbef-57cb919ccfba): Unable to establish connection to input-<xxxxx>.cloud.splunk.com: sslv3 alert handshake failure

0 Karma

mdickey_splunk
Splunk Employee
Splunk Employee

Please try using your splunk web UI port (8000?) instead of the data port (9997) for splunk_stream_app_location. It uses this to pull down configuration information via the REST API. Your splunkd forwarder will send the events from stream to port 9997 assuming it is configured properly via outputs.conf.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...