I want to configure a server as a heavy forwarder. I'm not clear that I understand how to ship the logs from the heavy forwarder to the indexer. Does an input have to be configured on the forwarder?
Seems my indexer is listening on the configured port 5000 okay.
At this point, I have configured the forwarder with defaults (except I'm using port 5000). The same for the receiving indexer (port 5000 again.) But I am not getting any data from the heavy forwarder... does an input have to be configured on the forwarder????
Splunkd.Log says something is wrong with SSL ( which I did not configure)
Is there a complete configuration guide for forwarders? The documentation seems so inadequate to completely describe the steps to set this up...
04-12-2011 13:11:08.603 ERROR TcpInputFd - SSL Error = error:00000000:lib(0):func(0):reason(0) 04-12-2011 13:11:08.603 ERROR TcpInputFd - ACCEPT_RESULT=0 VERIFY_RESULT=0 04-12-2011 13:11:08.603 ERROR TcpInputFd - SSL Error for fd from HOST:(myhost name)
thanks in advance.
asked 12 Apr '11, 18:03
Hi, here in mine environmental i've more than 600 universal forwarders sending data to 2 heavy forwarder. So try it this:
outputs.conf on heavy forwarder
server=IP INDEXER A:5000,IP INDEXER B:5000
inputs.conf on heavy forwarder
inputs.conf on indexer
outputs.conf on universal forwarder
server=IP HEAVY FORWARDER A:7700,IP HEAVY FORWARDER A:7700
answered 12 Apr '11, 18:28