Getting Data In

Trouble receiving information over TCP port

Golloway14
New Member

My IT department is currently attempting to set up a Splunk server. We have a Linux server forwarding to our Splunk server over a TCP port. The Linux server says it is forwarding to the server and our splunk server is receiving on the correct port but we are unable to get any information. Are there any common errors that we could be making? I tried searching for solutions to this problem but unfortunately came up empty handed.

Tags (4)
0 Karma

Ayn
Legend

Check splunkd.log for errors. A common error is to setup the wrong kind of port - you should be setting up a receiving port under "forwarding and receiving" instead of setting up a raw TCP input - or, in config file language, you want to use a splunktcp input, not tcp.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...