|
Hi, FORWARDER: inputs.conf in search/local: outputs.conf in search/local: [tcpout-server://10.1.1.1:514] stop/start log: INDEXER: inputs.conf in system/local: |
|
Did you happen to enable LWF in the last 5 days/since setting up the forwarder? The index parameter in inputs.conf on a LWF is not honored. It needs to be a regular forwarding if you want to perform routing to an index other than the default. Thanks for updating your description. Can you try adding this to the inputs.conf on the indexer? [monitor:///mnt/nagios/nagios.log] Also, did you try enabling "index and forward" on the forwarder to ensure that data is indeed getting indexed and to the correct index? Then we can rule out any input config issues. enabled SplunkForwarder. stoppped. started. still no luck.
(14 Sep '10, 18:52)
drewbfl
is index=nagios created on the indexer?
(14 Sep '10, 19:12)
hulahoop ♦
if it is, then try enabling local indexing on the forwarder to ensure there is nothing wrong with the input config. you'll probably have to create the nagios index temporarily on the forwarder.
(14 Sep '10, 19:22)
hulahoop ♦
i should also note, if you want to use the LWF, then i believe you can put the index=nagios setting on the indexer.
(14 Sep '10, 19:26)
hulahoop ♦
it is on the indexer. interestingly, the latest event in the nagios index is accurate. it must be pulling that from the syslog source. the source and sourcetype on the main search app still have the stale numbers.
(14 Sep '10, 20:40)
drewbfl
would you please update your question with inputs.conf from forwarder and indexer?
(14 Sep '10, 21:41)
hulahoop ♦
i added it above. thanks
(14 Sep '10, 22:24)
drewbfl
Didn't help. I tried adding it to both system/local and search/local inputs.confs and it didn't help.
(15 Sep '10, 21:37)
drewbfl
I'm sorry these steps haven't produced any different results for you. Have you tried enabling "index and forward" on the forwarder? If that does not produce the correct result, then I would recommend opening a ticket with the Splunk support team to have your configuration files reviewed in detail.
(16 Sep '10, 00:17)
hulahoop ♦
I really don't want the forwarder to do any indexing, it doesn't have the cycles nor should it need to. Isn't this a common thing everyone does with the product?
(17 Sep '10, 14:15)
drewbfl
I just mean to enable it for debugging purposes.
(20 Sep '10, 17:04)
hulahoop ♦
using
(22 Dec '10, 23:29)
gkanapathy ♦
showing 5 of 12
show 7 more comments ▼
|
