<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing forwarders showing incorrect results. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314835#M58943</link>
    <description>&lt;P&gt;i think that this lookup is being updated every period of time (interval), maybe the forwarder was down, the DMC picked it as "down" and it came back up before the now search that populates the lookup was fired ...&lt;/P&gt;</description>
    <pubDate>Wed, 28 Feb 2018 13:17:53 GMT</pubDate>
    <dc:creator>adonio</dc:creator>
    <dc:date>2018-02-28T13:17:53Z</dc:date>
    <item>
      <title>Missing forwarders showing incorrect results.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314834#M58942</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Within DMC there is Missing forwarders alert and the alert is flagging one of the host as missing but we can see data coming from that host in splunk. Its incorrect result from the alert, can someone provide an insight as to why this would be happening.&lt;/P&gt;

&lt;P&gt;| inputlookup dmc_forwarder_assets&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:13:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314834#M58942</guid>
      <dc:creator>Juhi28</dc:creator>
      <dc:date>2020-09-29T18:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Missing forwarders showing incorrect results.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314835#M58943</link>
      <description>&lt;P&gt;i think that this lookup is being updated every period of time (interval), maybe the forwarder was down, the DMC picked it as "down" and it came back up before the now search that populates the lookup was fired ...&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 13:17:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314835#M58943</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2018-02-28T13:17:53Z</dc:date>
    </item>
    <item>
      <title>Re: Missing forwarders showing incorrect results.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314836#M58944</link>
      <description>&lt;P&gt;yes forwarder was configured to collect data every 24 hours so was showing incorrect results even when it was up. Also curious to know if we can configure forwarders to collect data hourly [instead of 24 hours] so that DMC gives us an updated stats. ie. Data Collection Interval = hourly&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 04:34:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314836#M58944</guid>
      <dc:creator>Juhi28</dc:creator>
      <dc:date>2018-03-01T04:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Missing forwarders showing incorrect results.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314837#M58945</link>
      <description>&lt;P&gt;Have you tried to add it to a custom group then removing the custome group/label?&lt;/P&gt;

&lt;P&gt;Not sure, why but it seems an ongoing bug&lt;/P&gt;</description>
      <pubDate>Fri, 09 Mar 2018 09:42:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314837#M58945</guid>
      <dc:creator>valiquet</dc:creator>
      <dc:date>2018-03-09T09:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Missing forwarders showing incorrect results.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314838#M58946</link>
      <description>&lt;P&gt;hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/96358"&gt;@Juhi28&lt;/a&gt; and &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213662"&gt;@valiquet&lt;/a&gt;, &lt;BR /&gt;
I was facing the same problem as you. I was getting several Forwared "missing" alerts because I had done the Forwared reboot on the server and Splunk assigned a new GUID for the installation making the server think the old one was inaccessible. To resolve this issue you need to do the following: Settings&amp;gt; Monitoring Console&amp;gt; Settings&amp;gt; Forwarder Monitoring Setup and click on "Rebuild Forwarder assets" you will see that the alerts are gone.&lt;/P&gt;

&lt;P&gt;you can also check that this Forwared are saved in the following file: /opt/splunk/etc/apps/splunk_monitoring_console/lookups/dmc_forwarder_assets.csv after Rebuild you will see that Splunk has removed the assets that were missing status&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:23:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314838#M58946</guid>
      <dc:creator>justodaniel</dc:creator>
      <dc:date>2020-09-29T20:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: Missing forwarders showing incorrect results.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314839#M58947</link>
      <description>&lt;P&gt;"Rebuild Forwarder assets" was the simple manual fix that worked this time around, forgot about that configuration option.  Will have to monitor to see if this reappears as I would not want to rely on this as a step to validate the missing forwarders alert.  Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 14:28:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314839#M58947</guid>
      <dc:creator>kevincmartin</dc:creator>
      <dc:date>2018-11-27T14:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Missing forwarders showing incorrect results.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314840#M58948</link>
      <description>&lt;P&gt;This is resolved.&lt;/P&gt;

&lt;P&gt;rebuilding asset table for last 4hours [or less] data updates the status of fwders.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 03:54:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Missing-forwarders-showing-incorrect-results/m-p/314840#M58948</guid>
      <dc:creator>Juhi28</dc:creator>
      <dc:date>2019-01-15T03:54:15Z</dc:date>
    </item>
  </channel>
</rss>

