The forwarder is installed and active, and monitoring a directory. Why is it not showing up in Storm? Is that the correct host? I had to manually add this forward-server, nothing was there by default.
./splunkforwarder/bin/splunk list forward-server
Active forwards:
forwarder.splunkstorm.com:9997
Configured but inactive forwards:
None
From $SPLUNK_HOME/var/log/splunk/splunkd.log
08-06-2013 16:15:44.150 +0000 INFO TailingProcessor - ...continuing.
08-06-2013 16:15:44.150 +0000 INFO TcpOutputProc - Connection to 50.17.56.245:9997 closed. Connection closed by server.
08-06-2013 16:15:44.154 +0000 INFO TcpOutputProc - Connected to idx=50.16.8.52:9997
08-06-2013 16:15:44.155 +0000 INFO TcpOutputProc - Connected to idx=107.22.148.176:9997
08-06-2013 16:15:44.158 +0000 INFO TcpOutputProc - Connection to 50.16.8.52:9997 closed. Connection closed by server.
08-06-2013 16:15:44.159 +0000 INFO TcpOutputProc - Connection to 107.22.148.176:9997 closed. Connection closed by server.
08-06-2013 16:15:44.164 +0000 INFO TcpOutputProc - Connected to idx=50.16.8.52:9997
08-06-2013 16:15:44.168 +0000 INFO TcpOutputProc - Connection to 50.16.8.52:9997 closed. Connection closed by server.
08-06-2013 16:15:44.168 +0000 WARN TcpOutputProc - Applying quarantine to ip=50.16.8.52 port=9997 _numberOfFailures=2
08-06-2013 16:15:44.184 +0000 INFO TcpOutputProc - Connected to idx=50.16.8.52:9997
08-06-2013 16:15:44.189 +0000 INFO TcpOutputProc - Connection to 50.16.8.52:9997 closed. Connection closed by server.
08-06-2013 16:15:49.150 +0000 INFO TailingProcessor - Could not send data to output queue (parsingQueue), retrying...
08-06-2013 16:16:14.111 +0000 INFO TcpOutputProc - Connected to idx=107.20.29.58:9997 using ACK.
I added a directory to monitor.
splunkforwarder/bin/splunk list monitor
Monitored Directories:
$SPLUNK_HOME/var/log/splunk/splunkd.log
$SPLUNK_HOME/var/spool/splunk/...stash_new
/home/ubuntu/app/logs/*.log
/home/ubuntu/app/logs/check_inbox_2013_07_18.log
/home/ubuntu/app/logs/check_inbox_2013_08_05.log
/home/ubuntu/app/logs/check_inbox_2013_08_06.log
Monitored Files:
$SPLUNK_HOME/etc/splunk.version