I have one Indexer (IDX) receiving data from one Heavy Forwarder (HF).
I configured SSL in both of them and now the Heavy Forwarder is not sending data to the Indexer. However the TCP connection is established between them when doing $ netstat -an.
I activated debug messages to appear on logs and I have the following error in "splunkd.log":
My configurations are similar to the ones here:
Thank you in advance
asked 19 Apr '12, 02:06
It turns out the configuration at inputs.conf:
didn't match with the configuration at outputs.conf:
It was just a matter of setting that right by putting everything alike int both files.
answered 19 Apr '12, 02:42