<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Heavy forwarder not sending logs (Windows) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336034#M62131</link>
    <description>&lt;P&gt;thanks!  i'll try when it happens again!&lt;/P&gt;</description>
    <pubDate>Mon, 30 Oct 2017 05:14:46 GMT</pubDate>
    <dc:creator>hkizuka</dc:creator>
    <dc:date>2017-10-30T05:14:46Z</dc:date>
    <item>
      <title>Heavy forwarder not sending logs (Windows)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336030#M62127</link>
      <description>&lt;P&gt;I've got an issue with HF not sending the logs to indexer.&lt;BR /&gt;
Does anyone have experience with something like this?&lt;/P&gt;

&lt;P&gt;HF was sending the log to indexer as it should until yesterday.&lt;BR /&gt;
at one moment, indexer OS somehow got shutdown and HF didn't send any logs including internal logs even after the indexer was booted and connection was established.&lt;/P&gt;

&lt;P&gt;HF:Windows Server 2012&lt;BR /&gt;
indexer:Windows Server 2016&lt;BR /&gt;
Splunk version : 6.6.3&lt;/P&gt;

&lt;P&gt;when I checked splunkd.log in HF, I saw logs written as below&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;10-27-2017 09:07:18.938 +0900 WARN  TcpOutputProc - Tcpout Processor: The TCP output processor has paused the data flow. Forwarding to output group splunk01 has been blocked for 49250 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.&lt;BR /&gt;
10-27-2017 09:07:22.168 +0900 INFO  TcpOutputProc - Removing quarantine from idx=xxx.xxx.xxx.xxx:9997&lt;BR /&gt;
10-27-2017 09:07:22.199 +0900 INFO  TcpOutputProc - Connected to idx=xxx.xxx.xxx.xxx:9997, pset=0, reuse=0.&lt;BR /&gt;
10-27-2017 09:07:22.714 +0900 INFO  TailReader -   ...continuing.&lt;BR /&gt;
10-27-2017 09:07:22.885 +0900 INFO  LMStackMgr - should rollover=true because _lastRolloverTime=1508943600 lastRolloverDay=1508943600 snappedNow=1509030000&lt;BR /&gt;
10-27-2017 09:07:22.901 +0900 INFO  LMStackMgr - finished rollover, new lastRolloverTime=1509062842&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;it seems like HF did not read the new log file which it should.&lt;BR /&gt;
after i reboot the HF splunkd, it started to send all logs again.&lt;/P&gt;

&lt;P&gt;does anyone have any idea for the work-around other than rebooting HF's splunkd?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 06:18:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336030#M62127</guid>
      <dc:creator>hkizuka</dc:creator>
      <dc:date>2017-10-27T06:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not sending logs (Windows)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336031#M62128</link>
      <description>&lt;P&gt;are you connected to your Indexers directly or using indexerDiscovery?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 12:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336031#M62128</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-10-27T12:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not sending logs (Windows)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336032#M62129</link>
      <description>&lt;P&gt;Did you try reloading the inputs?&lt;/P&gt;

&lt;P&gt;./splunk _internal call /services/data/inputs/monitor/_reload -auth admin:changeme&lt;/P&gt;

&lt;P&gt;It might help.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:30:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336032#M62129</guid>
      <dc:creator>peterchenadded</dc:creator>
      <dc:date>2020-09-29T16:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not sending logs (Windows)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336033#M62130</link>
      <description>&lt;P&gt;looking at the indexer directly.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 05:14:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336033#M62130</guid>
      <dc:creator>hkizuka</dc:creator>
      <dc:date>2017-10-30T05:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Heavy forwarder not sending logs (Windows)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336034#M62131</link>
      <description>&lt;P&gt;thanks!  i'll try when it happens again!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 05:14:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-forwarder-not-sending-logs-Windows/m-p/336034#M62131</guid>
      <dc:creator>hkizuka</dc:creator>
      <dc:date>2017-10-30T05:14:46Z</dc:date>
    </item>
  </channel>
</rss>

