<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy forwarder not sending syslog to indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-syslog-to-indexer/m-p/574195#M101520</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230532"&gt;@johnlzy0408&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you already checked &lt;EM&gt;splunkd.log&lt;/EM&gt; if there is any &lt;EM&gt;ERROR&lt;/EM&gt; log that might clarify the problem?&lt;BR /&gt;Have you checked if the communication between HF and Indexer is OK on port 9997.&lt;/P&gt;&lt;P&gt;Or if Iptables could be blocking this communication?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please provide more details of the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;James \°/&lt;/P&gt;</description>
    <pubDate>Tue, 09 Nov 2021 13:02:56 GMT</pubDate>
    <dc:creator>James_ACN</dc:creator>
    <dc:date>2021-11-09T13:02:56Z</dc:date>
    <item>
      <title>Heavy forwarder not sending syslog to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-syslog-to-indexer/m-p/574152#M101515</link>
      <description>&lt;P&gt;Previously, my heavy forwarder is working fine. Able to search from latest logs in my searchhead. But upon testing another app for another SIEM in the heavy forwarder, it has been routing to there since. But after the POC ended, we want to switch back to sending it back to our splunk indexer.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We remove the app for the SIEM and left with our outputs for this forwarder which is towards the splunk indexer IP. I tried restarting the splunk service in this heavy forwarder but still unable to search those host in the searchhead.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything to look out for?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 09:07:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-syslog-to-indexer/m-p/574152#M101515</guid>
      <dc:creator>johnlzy0408</dc:creator>
      <dc:date>2021-11-09T09:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not sending syslog to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-syslog-to-indexer/m-p/574195#M101520</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230532"&gt;@johnlzy0408&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you already checked &lt;EM&gt;splunkd.log&lt;/EM&gt; if there is any &lt;EM&gt;ERROR&lt;/EM&gt; log that might clarify the problem?&lt;BR /&gt;Have you checked if the communication between HF and Indexer is OK on port 9997.&lt;/P&gt;&lt;P&gt;Or if Iptables could be blocking this communication?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please provide more details of the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;James \°/&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 13:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-syslog-to-indexer/m-p/574195#M101520</guid>
      <dc:creator>James_ACN</dc:creator>
      <dc:date>2021-11-09T13:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not sending syslog to indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-syslog-to-indexer/m-p/574221#M101523</link>
      <description>&lt;P&gt;Hi James,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checks on the splunkd comes out this few errors&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;11-09-2021 22:18:40.901 +0800 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;11-09-2021 22:18:45.796 +0800 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;11-09-2021 22:18:50.100 +0800 INFO HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_192.168.x.xxx_8089_splunk-forwardersg.ifastfinancial.local_splunk-forwarder02_08A348A2-5753-4968-8FC4-F4477414E56B&lt;BR /&gt;11-09-2021 22:18:50.797 +0800 INFO TailReader - Continuing...&lt;BR /&gt;11-09-2021 22:18:50.901 +0800 INFO TailReader - ...continuing.&lt;BR /&gt;11-09-2021 22:18:54.746 +0800 INFO TcpOutputProc - Found currently active indexer. Connected to idx=192.168.x.xxx:9997, reuse=1.&lt;BR /&gt;11-09-2021 22:18:55.956 +0800 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;11-09-2021 22:19:05.957 +0800 INFO TailReader - ...continuing.&lt;BR /&gt;11-09-2021 22:19:10.801 +0800 WARN TailReader - Could not send data to output queue (parsingQueue), retrying...&lt;BR /&gt;11-09-2021 22:19:20.802 +0800 INFO TailReader - Continuing...&lt;BR /&gt;11-09-2021 22:19:24.638 +0800 INFO TcpOutputProc - Found currently active indexer. Connected to idx=192.168.x.xxx:9997, reuse=1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Connection from Heavy forwarder to indexer is fine,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying 192.168.x.xx...&lt;BR /&gt;Connected to 192.168.x.xxx.&lt;BR /&gt;Escape character is '^]'.&lt;BR /&gt;^]&lt;/P&gt;&lt;P&gt;11-09-2021 23:30:07.713 +0800 INFO TcpOutputProc - Found currently active indexer. Connected to idx=192.168.x.xxx:9997, reuse=1.&lt;BR /&gt;11-09-2021 23:30:37.607 +0800 INFO TcpOutputProc - Found currently active indexer. Connected to idx=192.168.x.xxx:9997, reuse=1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 15:39:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-syslog-to-indexer/m-p/574221#M101523</guid>
      <dc:creator>johnlzy0408</dc:creator>
      <dc:date>2021-11-09T15:39:52Z</dc:date>
    </item>
  </channel>
</rss>

