<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why our Universal Forwarder frequently stop forwarding logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329004#M61051</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;Good Day, I have a problem with our universal forwarder, it frequently stops forwarding data. When the problem occur, my temporary resolution is to restart the forwarder and it will forward data again, however, the next day problem will occur again. It happen almost every day. What could be the solution here?&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Universal Forwarder version: 6.2.6 (build 274160)&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Dan&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jun 2017 03:44:29 GMT</pubDate>
    <dc:creator>dantimola</dc:creator>
    <dc:date>2017-06-07T03:44:29Z</dc:date>
    <item>
      <title>Why our Universal Forwarder frequently stop forwarding logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329004#M61051</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;Good Day, I have a problem with our universal forwarder, it frequently stops forwarding data. When the problem occur, my temporary resolution is to restart the forwarder and it will forward data again, however, the next day problem will occur again. It happen almost every day. What could be the solution here?&lt;/P&gt;

&lt;P&gt;&lt;EM&gt;Universal Forwarder version: 6.2.6 (build 274160)&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Dan&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 03:44:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329004#M61051</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-06-07T03:44:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why our Universal Forwarder frequently stop forwarding logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329005#M61052</link>
      <description>&lt;P&gt;Did you check whether the UF also stops sending _internal logs? Please show us your splunkd.log and the metrics.log from the time the forwarder stopped sending logs.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 07:04:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329005#M61052</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2017-06-07T07:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why our Universal Forwarder frequently stop forwarding logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329006#M61053</link>
      <description>&lt;P&gt;Here's splunkd.log before the problem occurred.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3011iB20A78C09FC3547E/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 07:11:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329006#M61053</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-06-07T07:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Why our Universal Forwarder frequently stop forwarding logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329007#M61054</link>
      <description>&lt;P&gt;Could you filter your internal events for any errors, please? Right now, it's hard to tell why the connection got interrupted.&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 08:22:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329007#M61054</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2017-06-07T08:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Why our Universal Forwarder frequently stop forwarding logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329008#M61055</link>
      <description>&lt;P&gt;06-07-2017 17:11:07.135 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:11:12.923 +0800 WARN  TcpOutputProc - Raw connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:11:12.923 +0800 INFO  TcpOutputProc - Ping connection to idx=IP:9997 timed out. continuing connections&lt;BR /&gt;
06-07-2017 17:11:42.875 +0800 WARN  TcpOutputProc - Cooked connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:11:42.875 +0800 WARN  TcpOutputProc - Raw connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:11:42.875 +0800 INFO  TcpOutputProc - Ping connection to idx=IP:9997 timed out. continuing connections&lt;BR /&gt;
06-07-2017 17:12:02.718 +0800 WARN  TcpOutputProc - Cooked connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:12:07.164 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:12:07.164 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:12:07.180 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:13:00.189 +0800 WARN  TcpOutputProc - Forwarding to indexer group group1 blocked for 100 seconds.&lt;BR /&gt;
06-07-2017 17:13:07.193 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:13:07.209 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:13:07.224 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:13:12.372 +0800 WARN  TcpOutputProc - Raw connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:13:12.372 +0800 INFO  TcpOutputProc - Ping connection to idx=IP:9997 timed out. continuing connections&lt;BR /&gt;
06-07-2017 17:13:23.105 +0800 INFO  TcpOutputProc - Connected to idx=IP:9998&lt;BR /&gt;
06-07-2017 17:17:51.067 +0800 &lt;STRONG&gt;ERROR&lt;/STRONG&gt; TailReader - File will not be read, seekptr checksum did not match (file=C:\Program Files (x86)\CyberArk\Password Manager\Logs\ThirdParty\HP_pseudo-ISDP-Root-CCBDPD02_logadm.Debug.log).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;BR /&gt;
06-07-2017 17:17:51.083 +0800 &lt;STRONG&gt;ERROR&lt;/STRONG&gt; TailReader - File will not be read, seekptr checksum did not match (file=C:\Program Files (x86)\CyberArk\Password Manager\Logs\ThirdParty\HP_pseudo-ISD VA-Root-CCBDPD02_secadmin.Debug.log).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:19:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329008#M61055</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2020-09-29T14:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why our Universal Forwarder frequently stop forwarding logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329009#M61056</link>
      <description>&lt;P&gt;What does Cooked connection and Ping connection means beside of network error?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jun 2017 09:27:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329009#M61056</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2017-06-07T09:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Why our Universal Forwarder frequently stop forwarding logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329010#M61057</link>
      <description>&lt;P&gt;06-07-2017 17:11:07.135 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:11:12.923 +0800 WARN  TcpOutputProc - Raw connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:11:12.923 +0800 INFO  TcpOutputProc - Ping connection to idx=IP:9997 timed out. continuing connections&lt;BR /&gt;
06-07-2017 17:11:42.875 +0800 WARN  TcpOutputProc - Cooked connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:11:42.875 +0800 WARN  TcpOutputProc - Raw connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:11:42.875 +0800 INFO  TcpOutputProc - Ping connection to idx=IP:9997 timed out. continuing connections&lt;BR /&gt;
06-07-2017 17:12:02.718 +0800 WARN  TcpOutputProc - Cooked connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:12:07.164 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:12:07.164 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:12:07.180 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:13:00.189 +0800 WARN  TcpOutputProc - Forwarding to indexer group group1 blocked for 100 seconds.&lt;BR /&gt;
06-07-2017 17:13:07.193 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:13:07.209 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:13:07.224 +0800 INFO  HttpPubSubConnection - Running phone uri=/services/broker/phonehome/connection_IP_8089_IP_pamapd02_508640B8-DCCC-43F7-BAEA-C19506B7C372&lt;BR /&gt;
06-07-2017 17:13:12.372 +0800 WARN  TcpOutputProc - Raw connection to ip=IP:9997 timed out&lt;BR /&gt;
06-07-2017 17:13:12.372 +0800 INFO  TcpOutputProc - Ping connection to idx=IP:9997 timed out. continuing connections&lt;BR /&gt;
06-07-2017 17:13:23.105 +0800 INFO  TcpOutputProc - Connected to idx=IP:9998&lt;BR /&gt;
06-07-2017 17:17:51.067 +0800 ERROR TailReader - File will not be read, seekptr checksum did not match (file=C:\Program Files (x86)\CyberArk\Password Manager\Logs\ThirdParty\HP_pseudo-ISDP-Root-CCBDPD02_logadm.Debug.log).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;BR /&gt;
06-07-2017 17:17:51.083 +0800 ERROR TailReader - File will not be read, seekptr checksum did not match (file=C:\Program Files (x86)\CyberArk\Password Manager\Logs\ThirdParty\HP_pseudo-ISD VA-Root-CCBDPD02_secadmin.Debug.log).  Last time we saw this initcrc, filename was different.  You may wish to use larger initCrcLen for this sourcetype, or a CRC salt on this source.  Consult the documentation or file a support case online at &lt;A href="http://www.splunk.com/page/submit_issue" target="_blank"&gt;http://www.splunk.com/page/submit_issue&lt;/A&gt; for more info.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:19:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-our-Universal-Forwarder-frequently-stop-forwarding-logs/m-p/329010#M61057</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2020-09-29T14:19:41Z</dc:date>
    </item>
  </channel>
</rss>

