Posted on July 6, 2015 2:27 pm
 |  Asked by Tobias Gabriel Gabriel
Print Friendly, PDF & Email

Hi community,

we´ve an Arista 7150 with firmware 4.14.5F running. I´ve installed the splunk extentions and it running well. I ´ve all data in the splunk app but no interface data.

show splunk-forwarder
Splunk Forwarder Extension:
Arista EOS Splunk Extension: 1.1.1
Splunk Universal Forwarder: 6.2.3

Administrative Status: enabled
Operational Status: (VRF: default): running

eAPI Client Configuration:
Username: admin
Password: Set
Protocol: https
Port: 443
Enable Password: Set

Indexers Configured:

Items to index: (max-data-rate is 256 Kbps)
Switch Inventory: enabled (30m 0s intervals)
Topology Information: enabled (30m 0s intervals)
Interface Statistics: enabled (3m 0s intervals)
Latency Analyzer (LANZ): enabled (30m 0s intervals)
Syslog: enabled

I played around with the interface statistics counter but still no interface data in the splunk app.



Answered on July 8, 2015 3:54 pm

Hi Tobias,

Go to AristaSplunk Dashboard and search for ”host=* error_msg=*” and check what the results are for your switch?

If this doesn’t yield any result, on your switch, from bash, can you run

/usr/bin/eosfacts -r splunk.counters -c /persist/sys/splunkforwarder/etc/arista.conf

and report back the results?

Additionally, can you please try out the recent release-1.2  to see if this fixes it



Answered on July 9, 2015 1:16 pm


I´ve found in Splunk tap search sources this output:

[debug] [Errno 111] Connection refused ERROR: could not communicate with eAPI

ERROR: [Errno 111] Connection refused

But still no idea why. All the other data works fine…



Hi Tobias,

Did you get a chance to try out the recent bug fix release-1.1.2?

(Sakti Aishwarya Arunachalam Arunachalam at July 28, 2015 5:06 pm)
Posted by Karlheinz Mueller
Answered on February 7, 2020 1:36 pm

Hi all.

Did anyone figure out the issue with the "connection refused" problem?
I run into the same.

Arista 7280SE

eAPI configured and running and availabe. I can login via browser with the credentials configured for the splunk forwarder.

But I get the following error:
[switch ~]$ /usr/bin/eosfacts -r splunk.counters -c /persist/sys/splunkforwarder/etc/arista.conf
No handlers could be found for logger "pyeapi.eapilib"
ERROR: Socket error during eAPI connection: [Errno 111] Connection refused

Thank you

quick test:

daemon splunkforwarder
exec /usr/bin/SplunkAgent
option eapi_protocol value socket
no shutdown
management api http-commands
protocol http
protocol unix-socket
no shutdown

[admin@leafb ~]$ /usr/bin/eosfacts -r splunk.counters -c /persist/sys/splunkforwarder/etc/arista.conf
t=1582767080.16 AristaIfCounters switchname="" interface="Ethernet8" linkStatus="notconnect" description="" speed="25000000"
t=1582767080.16 AristaIfCounters switchname="" interface="Ethernet9" linkStatus="notconnect" description="" speed="25000000"

What is your splunk and eapi config?

(Tamas Plugor at February 27, 2020 1:47 am)

Post your Answer

You must be logged in to post an answer.