we´ve an Arista 7150 with firmware 4.14.5F running. I´ve installed the splunk extentions and it running well. I ´ve all data in the splunk app but no interface data.
show splunk-forwarder Splunk Forwarder Extension: Arista EOS Splunk Extension: 1.1.1 Splunk Universal Forwarder: 6.2.3 Administrative Status: enabled Operational Status: (VRF: default): running eAPI Client Configuration: Username: admin Password: Set Protocol: https Port: 443 Enable Password: Set Indexers Configured: 192.168.30.189:9997 Items to index: (max-data-rate is 256 Kbps) Switch Inventory: enabled (30m 0s intervals) Topology Information: enabled (30m 0s intervals) Interface Statistics: enabled (3m 0s intervals) Latency Analyzer (LANZ): enabled (30m 0s intervals) Syslog: enabled
I played around with the interface statistics counter but still no interface data in the splunk app.
Go to AristaSplunk Dashboard and search for ”host=* error_msg=*” and check what the results are for your switch?
If this doesn’t yield any result, on your switch, from bash, can you run
/usr/bin/eosfacts -r splunk.counters -c /persist/sys/splunkforwarder/etc/arista.conf
and report back the results?
Additionally, can you please try out the recent release-1.2 to see if this fixes it
I´ve found in Splunk tap search sources this output:
[debug] [Errno 111] Connection refused ERROR: could not communicate with eAPI
ERROR: [Errno 111] Connection refused
But still no idea why. All the other data works fine…
Did you get a chance to try out the recent bug fix release-1.1.2?
Did anyone figure out the issue with the "connection refused" problem?
eAPI configured and running and availabe. I can login via browser with the credentials configured for the splunk forwarder.
But I get the following error:
What is your splunk and eapi config?
Post your Answer
You must be logged in to post an answer.