<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunkforwarder stopped sending data randomly in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunkforwarder-stopped-sending-data-randomly/m-p/368945#M13587</link>
    <description>&lt;P&gt;hello there,&lt;BR /&gt;
first check if you can see data from forwarders in index=_internal&lt;BR /&gt;
if so, it means the forwarders do send data to indexers and therefore check inputs&lt;BR /&gt;
another option is to follow that article:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/Troubleshooting/Cantfinddata"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
    <pubDate>Fri, 23 Jun 2017 01:55:44 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2017-06-23T01:55:44Z</dc:date>
    <item>
      <title>Splunkforwarder stopped sending data randomly</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunkforwarder-stopped-sending-data-randomly/m-p/368944#M13586</link>
      <description>&lt;P&gt;Hey Guys!&lt;/P&gt;

&lt;P&gt;So I have 2 forwarders they had stopped sending current data, I looked over the splunk config with a splunk contractor and found their was nothing wrong with the splunk config. So he told me to check and see if there were possibly any firewalls rules blocking traffic, so I went to the FW team and everything seems good from that aspect because out of nowhere one of the servers starts reporting data again, but the other server is still no reporting data......would anybody have any idea what could be wrong?&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;I checked to make sure the splunkwarder was running with the &lt;STRONG&gt;./splunk status&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;I made sure the files were being monitored on the forwarder with the &lt;STRONG&gt;./splunk list monitor&lt;/STRONG&gt; command&lt;/LI&gt;
&lt;LI&gt;I made sure the timestamp was okay by checking the time on the event versus its _time (but the servers are located in eastern time so time format shouldn't be an issue) (And plus the other server started pulling current data, and they have the same splunk config)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Would there be any other thing I should check that I haven't listed above?&lt;/P&gt;

&lt;P&gt;Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 20:34:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunkforwarder-stopped-sending-data-randomly/m-p/368944#M13586</guid>
      <dc:creator>qfulgham</dc:creator>
      <dc:date>2017-06-22T20:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunkforwarder stopped sending data randomly</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunkforwarder-stopped-sending-data-randomly/m-p/368945#M13587</link>
      <description>&lt;P&gt;hello there,&lt;BR /&gt;
first check if you can see data from forwarders in index=_internal&lt;BR /&gt;
if so, it means the forwarders do send data to indexers and therefore check inputs&lt;BR /&gt;
another option is to follow that article:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.6.1/Troubleshooting/Cantfinddata"&gt;http://docs.splunk.com/Documentation/Splunk/6.6.1/Troubleshooting/Cantfinddata&lt;/A&gt;&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 01:55:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunkforwarder-stopped-sending-data-randomly/m-p/368945#M13587</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-06-23T01:55:44Z</dc:date>
    </item>
  </channel>
</rss>

