<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Universal Forwarder stop Forwarding in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-stop-Forwarding/m-p/109265#M22980</link>
    <description>&lt;P&gt;How did you set your forwarder? Using a Deployment Manager?&lt;/P&gt;

&lt;P&gt;Also what O/S is it running on? I've seen some similar behaviour on Windows forwarders in the past.&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2015 19:26:28 GMT</pubDate>
    <dc:creator>Stefan</dc:creator>
    <dc:date>2015-05-13T19:26:28Z</dc:date>
    <item>
      <title>Universal Forwarder stop Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-stop-Forwarding/m-p/109263#M22978</link>
      <description>&lt;P&gt;Im using Splunk Cloud, &lt;/P&gt;

&lt;P&gt;and every once in a while, im getting this error &lt;/P&gt;

&lt;P&gt;05-13-2015 09:10:34.891 -0400 WARN  TcpOutputProc - Forwarding to indexer group splunkcloud blocked for 207000 seconds.&lt;/P&gt;

&lt;P&gt;After that, my indexer is not indexing anymore.&lt;BR /&gt;
Inside the log, I continue to see thing like this : &lt;/P&gt;

&lt;P&gt;05-13-2015 09:07:16.757 -0400 WARN  TcpOutputProc - Possible duplication of events with channel=source::WMI:AllReplicatedFolder|host::server1|WMI:AllReplicatedFolder|53003616, streamId=12722903640634641263, offset=516887 subOffset=1 on host=54.174.234.168:9997&lt;BR /&gt;
05-13-2015 09:07:16.757 -0400 WARN  TcpOutputProc - Possible duplication of events with channel=source::WMI:AllReplicatedFolder|host::server1|WMI:AllReplicatedFolder|53003616, streamId=12722903640634641263, offset=298120 subOffset=1 on host=54.174.234.168:9997&lt;/P&gt;

&lt;P&gt;So I guess the forwarder continue to gather informations from differents servers.&lt;/P&gt;

&lt;P&gt;I have to restart the service to make the cloud index again.&lt;/P&gt;

&lt;P&gt;This universal forwarder is making WMI request to 30 differents server and push information to the cloud.&lt;BR /&gt;
I have the exact same wmi.conf file on a "local test machine" wich is splunk enterprise 6.2.2 and it never stoped to index the same information.&lt;/P&gt;

&lt;P&gt;Any one have the solution ? Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 13:19:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-stop-Forwarding/m-p/109263#M22978</guid>
      <dc:creator>jeanfrederic</dc:creator>
      <dc:date>2015-05-13T13:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder stop Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-stop-Forwarding/m-p/109264#M22979</link>
      <description>&lt;P&gt;For some reason, It turned to be my Universal Forwarder that was sending "duplicate" by itself.&lt;/P&gt;

&lt;P&gt;My Splunk Enterprise Index was all right, around 2200 entries... and My Splunk Cloud was having 1 200 000 entries.&lt;BR /&gt;
They both use the same wmi.conf&lt;/P&gt;

&lt;P&gt;I dont know why I was having those duplicate.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 19:17:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-stop-Forwarding/m-p/109264#M22979</guid>
      <dc:creator>jeanfrederic</dc:creator>
      <dc:date>2015-05-13T19:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: Universal Forwarder stop Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-stop-Forwarding/m-p/109265#M22980</link>
      <description>&lt;P&gt;How did you set your forwarder? Using a Deployment Manager?&lt;/P&gt;

&lt;P&gt;Also what O/S is it running on? I've seen some similar behaviour on Windows forwarders in the past.&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2015 19:26:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Universal-Forwarder-stop-Forwarding/m-p/109265#M22980</guid>
      <dc:creator>Stefan</dc:creator>
      <dc:date>2015-05-13T19:26:28Z</dc:date>
    </item>
  </channel>
</rss>

