Hi Splunkers
I have a problem with a Modular Input in Splunk. I'm using the Monitoring of Java Virtual Machines with JMX app to push JMX data into Splunk.
This works with a new Installation from a heavy forwarder very well. After a time, the Java process exits with the following message:
ERROR ModularInput - Can't connect to Splunk REST API with the token [Splunk bgmFr7ozce8o6MsM_XSjtBctMT62B4QslXNLWRCLZUGHB_Dz9RjKGP8brkqFcpwdO97hb_0nqVFau7PVyBBGeQDzSmlFnKga98o6lutJODEz5d0ttl0knxtq0nF], either the token is invalid or SplunkD has exited : HTTP 401 -- call not properly authenticated
INFO Mapping - Loading mapping descriptors from jar:file:/opt/splunk/etc/apps/SPLUNK4JMX/bin/lib/jmxmodinput.jar!/mapping.XML
ERROR ModularInput - It has been determined via the REST API that all inputs have been disabled
Does someone have an idea why this problem occurs? I changed nothing on the heavy forwarder.
I can solve the Problem with a complete reinstallation of the heavy forwarder, but that cannot be the solution.
I am glad of any help.
Best regards,
Yanick
↧