Getting Data In

switch forwarders to new indexer

rameshlpatel
Communicator

Hi,

I have existing indexer with 6.0 version and same version for all forwarders.

Now we got new splunk physical server with version 6.1.1,

Not I am switching forwarder to new server by replacing server attribute. However its not able to forward to new.

please suggest me what i have to consider before moving to new server ? Is data file will affect to due to this ? Please suggest me solution.

outputs.conf
[tcpout]
defaultGroup=DBGroup

[tcpout:DBGroup]
server =alpputl018:9997

Tags (2)
0 Karma

linu1988
Champion

First step before migrating between platform is to check the network connectivty

Ping alpputl018
telnet alpputl018 "receiving_port/9997"

new server will not be having the receiving configured. Check it right away.

Check the forwarder logs what is the issue if is not able to connect.

Thanks,
L

0 Karma

rameshlpatel
Communicator

Not played with indexes.conf in old or new server.

0 Karma

harald_leitl
Path Finder

what about indexes.conf? same config on old and new server?

0 Karma

rameshlpatel
Communicator

Yes. its opened

0 Karma

harald_leitl
Path Finder

is tcp port 9997 open on new index server?

0 Karma

rameshlpatel
Communicator

Adding more details. _internal logs are seeing in new server but not application log.

0 Karma

rameshlpatel
Communicator

IS data monitoring pointer will affect due to this ?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...