Getting Data In

Why are servers connecting to my deployment server, but not the indexers?

JoeSco27
Communicator

I have created and deployed the following serverclass.conf stanza:

[serverClass:dt-exdata]
whitelist.0 = dt1exdata*
[serverClass:dt-exdata:app:dt-exdata-inputs]

and when i look on my deployment server under Settings >> Distributed environment >> Forwarder management >> I can see the clients phoneHome and the dt-exdata-inputs app being deployed to the dt1exdata servers. When i then go to my indexer i do not see any logs from those servers. I have had my network team telnet to my deployment server over port 8089 and to my indexer over port 9997 and the connections were both successful. I am not sure why i would be able to see the dt1exdata servers connecting to my deployment server but not my indexers.

We also checked one of the dt1exdata servers and the outputs.conf was pointing to the correct location and the dt-exdata-inputs app was in the apps directory.

0 Karma

chanfoli
Builder

The first place I would look in this case is in the splunkd.logs on your forwarders (SPLUNKHOME/var/log/splunk/splunkd.log) . I would look for messages about connections. I would also run SPLUNKHOME/bin/splunk list forward-server

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...