<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Forwarder with DB Connect : connection not closed with Splunk Indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-with-DB-Connect-connection-not-closed-with/m-p/386621#M69385</link>
    <description>&lt;P&gt;I am using Splunk Heavy Forwader with DB Connect to forward data to a Splunk Indexer instance.&lt;BR /&gt;
Although the HF is not forwarding any data, the connection is still established between the HF and the indexer. I'm talking about a connection that hasn't been closed for more than 3 days with no data sent!&lt;BR /&gt;
Is anyone having the same problem ? I could use some help, thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jun 2018 13:52:04 GMT</pubDate>
    <dc:creator>mbennani3492</dc:creator>
    <dc:date>2018-06-18T13:52:04Z</dc:date>
    <item>
      <title>Splunk Forwarder with DB Connect : connection not closed with Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-with-DB-Connect-connection-not-closed-with/m-p/386621#M69385</link>
      <description>&lt;P&gt;I am using Splunk Heavy Forwader with DB Connect to forward data to a Splunk Indexer instance.&lt;BR /&gt;
Although the HF is not forwarding any data, the connection is still established between the HF and the indexer. I'm talking about a connection that hasn't been closed for more than 3 days with no data sent!&lt;BR /&gt;
Is anyone having the same problem ? I could use some help, thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 13:52:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-with-DB-Connect-connection-not-closed-with/m-p/386621#M69385</guid>
      <dc:creator>mbennani3492</dc:creator>
      <dc:date>2018-06-18T13:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder with DB Connect : connection not closed with Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-with-DB-Connect-connection-not-closed-with/m-p/386622#M69386</link>
      <description>&lt;P&gt;That sounds appropriate; forwarders, both universal and heavy, will always try to have a connection open to an indexer. If you have just one indexer, I believe it will keep a single connection open until something interrupts that connection. The connection is probably not idle, either; the HF is probably forwarding data about its internal operation and that data should be in the &lt;CODE&gt;_internal&lt;/CODE&gt; index on your indexer.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 23:52:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-with-DB-Connect-connection-not-closed-with/m-p/386622#M69386</guid>
      <dc:creator>jtacy</dc:creator>
      <dc:date>2018-06-18T23:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Forwarder with DB Connect : connection not closed with Splunk Indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-with-DB-Connect-connection-not-closed-with/m-p/386623#M69387</link>
      <description>&lt;P&gt;Thanks for your answer.&lt;BR /&gt;
So you are saying that it is normal as long as the HF is sending its internal data to my indexer.&lt;BR /&gt;
Then how can I make him stop, and send only the data i want it to send ?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 12:28:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Forwarder-with-DB-Connect-connection-not-closed-with/m-p/386623#M69387</guid>
      <dc:creator>mbennani3492</dc:creator>
      <dc:date>2018-06-19T12:28:18Z</dc:date>
    </item>
  </channel>
</rss>

