<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does universal forwarder stops sending data and just sends data once restart is done? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stops-sending-data-and-just-sends/m-p/636623#M108875</link>
    <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;I have an issue with one forwarder, was working and suddenly stopped sending data to the Indexers.&lt;/P&gt;
&lt;P&gt;The Splunk services at the UF are running but the data is not sent to the Indexers. The internal logs are not sent either.&lt;/P&gt;
&lt;P&gt;But if I run a restart at the UF the logs are send but almost immediately are stopped again.&lt;/P&gt;
&lt;P&gt;I have checked the logs but I cannot find a logical reason for this to happen.&lt;/P&gt;
&lt;P&gt;I have changed the&lt;/P&gt;
&lt;PRE&gt;[inputproc]

max_fd = &amp;lt;integer&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;From 100 to 8192 then I restarted the splunk service.&lt;/P&gt;
&lt;P&gt;I have checked the ulimits and currently is in 6400.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I stop and start the service and I check the logs I cannot see any clue about can be happening, these are the logs that appears before the UF stops sending data:&lt;/P&gt;
&lt;P&gt;03-30-2023 05:07:26.260 +0200 INFO TailReader [20263 MainTailingThread] - Setting maxFDs to 8192&lt;/P&gt;
&lt;P&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize http_proxy from server.conf for splunkd. Please make sure that the http_proxy property is set as http_proxy=&lt;A href="http://host:port" target="_blank" rel="noopener"&gt;http://host:port&lt;/A&gt; in case HTTP proxying needs to be enabled.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize http_proxy from server.conf for splunkd. Please make sure that the http_proxy property is set as http_proxy=&lt;A href="http://host:port" target="_blank" rel="noopener"&gt;http://host:port&lt;/A&gt; in case HTTP proxying needs to be enabled.&lt;BR /&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize https_proxy from server.conf for splunkd. Please make sure that the https_proxy property is set as https_proxy=&lt;A href="http://host:port" target="_blank" rel="noopener"&gt;http://host:port&lt;/A&gt; in case HTTP proxying needs to be enabled.&lt;BR /&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize the proxy_rules setting from server.conf for splunkd. Please provide a valid set of proxy_rules in case HTTP proxying needs to be enabled.&lt;BR /&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize the no_proxy setting from server.conf for splunkd. Please provide a valid set of no_proxy rules in case HTTP proxying needs to be enabled.&lt;BR /&gt;03-30-2023 05:07:31.674 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.675 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.675 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.675 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.685 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.685 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.685 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.685 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.695 +0200 INFO AutoLoadBalancedConnectionStrategy [20259 TcpOutEloop] - Will resolve indexer names at 330.000 second interval.&lt;BR /&gt;03-30-2023 05:07:36.671 +0200 INFO TailReader [20266 tailreader0] - Batch input finished reading file='/opt/splunkforwarder/var/spool/splunk/tracker.log'&lt;BR /&gt;03-30-2023 05:07:37.774 +0200 INFO DC:DeploymentClient [20219 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;03-30-2023 05:07:49.774 +0200 INFO DC:DeploymentClient [20219 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After certain time I see the message "&lt;SPAN&gt;The TCP output processor has paused the data flow. Forwarding to host_dest&lt;/SPAN&gt;..."&lt;/P&gt;
&lt;P&gt;But I assume this is because the Splunkd is not able of send data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any idea about what can be going on?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2023 07:46:03 GMT</pubDate>
    <dc:creator>glpadilla_sol</dc:creator>
    <dc:date>2023-03-30T07:46:03Z</dc:date>
    <item>
      <title>Why does universal forwarder stops sending data and just sends data once restart is done?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stops-sending-data-and-just-sends/m-p/636623#M108875</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;I have an issue with one forwarder, was working and suddenly stopped sending data to the Indexers.&lt;/P&gt;
&lt;P&gt;The Splunk services at the UF are running but the data is not sent to the Indexers. The internal logs are not sent either.&lt;/P&gt;
&lt;P&gt;But if I run a restart at the UF the logs are send but almost immediately are stopped again.&lt;/P&gt;
&lt;P&gt;I have checked the logs but I cannot find a logical reason for this to happen.&lt;/P&gt;
&lt;P&gt;I have changed the&lt;/P&gt;
&lt;PRE&gt;[inputproc]

max_fd = &amp;lt;integer&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;From 100 to 8192 then I restarted the splunk service.&lt;/P&gt;
&lt;P&gt;I have checked the ulimits and currently is in 6400.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I stop and start the service and I check the logs I cannot see any clue about can be happening, these are the logs that appears before the UF stops sending data:&lt;/P&gt;
&lt;P&gt;03-30-2023 05:07:26.260 +0200 INFO TailReader [20263 MainTailingThread] - Setting maxFDs to 8192&lt;/P&gt;
&lt;P&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize http_proxy from server.conf for splunkd. Please make sure that the http_proxy property is set as http_proxy=&lt;A href="http://host:port" target="_blank" rel="noopener"&gt;http://host:port&lt;/A&gt; in case HTTP proxying needs to be enabled.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize http_proxy from server.conf for splunkd. Please make sure that the http_proxy property is set as http_proxy=&lt;A href="http://host:port" target="_blank" rel="noopener"&gt;http://host:port&lt;/A&gt; in case HTTP proxying needs to be enabled.&lt;BR /&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize https_proxy from server.conf for splunkd. Please make sure that the https_proxy property is set as https_proxy=&lt;A href="http://host:port" target="_blank" rel="noopener"&gt;http://host:port&lt;/A&gt; in case HTTP proxying needs to be enabled.&lt;BR /&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize the proxy_rules setting from server.conf for splunkd. Please provide a valid set of proxy_rules in case HTTP proxying needs to be enabled.&lt;BR /&gt;03-30-2023 05:07:31.013 +0200 INFO ProxyConfig [20259 TcpOutEloop] - Failed to initialize the no_proxy setting from server.conf for splunkd. Please provide a valid set of no_proxy rules in case HTTP proxying needs to be enabled.&lt;BR /&gt;03-30-2023 05:07:31.674 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.675 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.675 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.675 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.685 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.685 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.685 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.685 +0200 WARN TcpOutputProc [20259 TcpOutEloop] - 'sslCertPath' deprecated; use 'clientCert' instead&lt;BR /&gt;03-30-2023 05:07:31.695 +0200 INFO AutoLoadBalancedConnectionStrategy [20259 TcpOutEloop] - Will resolve indexer names at 330.000 second interval.&lt;BR /&gt;03-30-2023 05:07:36.671 +0200 INFO TailReader [20266 tailreader0] - Batch input finished reading file='/opt/splunkforwarder/var/spool/splunk/tracker.log'&lt;BR /&gt;03-30-2023 05:07:37.774 +0200 INFO DC:DeploymentClient [20219 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;03-30-2023 05:07:49.774 +0200 INFO DC:DeploymentClient [20219 PhonehomeThread] - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After certain time I see the message "&lt;SPAN&gt;The TCP output processor has paused the data flow. Forwarding to host_dest&lt;/SPAN&gt;..."&lt;/P&gt;
&lt;P&gt;But I assume this is because the Splunkd is not able of send data.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have any idea about what can be going on?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 07:46:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stops-sending-data-and-just-sends/m-p/636623#M108875</guid>
      <dc:creator>glpadilla_sol</dc:creator>
      <dc:date>2023-03-30T07:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: Universal forwarder stops sending data and just sends data once restart is done</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stops-sending-data-and-just-sends/m-p/636635#M108876</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/241395"&gt;@glpadilla_sol&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;some question to better understand the situation:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;at first, have you this kind of problems only on this UF?&lt;/LI&gt;&lt;LI&gt;if yes, should this UF send many logs?&lt;/LI&gt;&lt;LI&gt;could you have some network congestion problem in the netweork segment between the UF and Indexers?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;please try to modify the following parameters on&lt;/P&gt;&lt;P&gt;UF's server.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[queue]
maxSize = 10MB&lt;/LI-CODE&gt;&lt;P&gt;and UF's limits.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;maxKBps = 2048&lt;/LI-CODE&gt;&lt;P&gt;in this way you enlarge the dimension of the UF queue&lt;/P&gt;&lt;P&gt;obviously with following UF's Splunk restart&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2023 06:43:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-universal-forwarder-stops-sending-data-and-just-sends/m-p/636635#M108876</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-03-30T06:43:18Z</dc:date>
    </item>
  </channel>
</rss>

