Hi All
I'm trying Splunk for the first time - I'm sifting through the documentation and finding it difficult to ascertain how to install forwarder and do a very basic config with an indexer.
Installed it on my win xp desktop as the indexer and installed the forwader on a test Linux machine. The linux forwarder inputs.conf looks like this:
[tcpout]
defaultGroup = hostnameofwindowslaptop_9997
[tcpout:hostnameofwindowslaptop_9997]
server = hostnameofwindowslaptop:9997
[tcpout-server://hostnameofwindowslaptop:9997]
in the windows server logs i constantly get this:
07-27-2012 11:40:39.274 +0100 ERROR TcpOutputFd - Connection to host=forwarderIP:9997 failed
07-27-2012 11:40:39.274 +0100 WARN TcpOutputProc - Applying quarantine to idx=forwarderIP:9997 numberOfFailures=11
...and on the forwarder in the splunkd.log i get exactly the same error messages.
Can anyone give me any pointers to troubleshoot this? I've tried searching for errors in the web gui search bar over the passed 24 hours and it tells me there's no errors. My forwarder doesn't show in the 'datasources' bit on the search screen either. Bit stumped 😞 Thanks in advance!
... View more