<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why does forwarding stop until i restart splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45468#M8521</link>
    <description>&lt;P&gt;We are experiencing a few issues with our windows forwarders and one of them sounds like it might be the same. We have this issue where we get splunk internal logs constantly, but monitored files are only sent on shutdown of the universal forwarder. This problem appears to be that the splunk forwarder was trying to "restart" too quickly. When we tried to restart the forwarder we received an error message that the process was taking too long - but it appeared stopped in the windows serverice listing so we started it up again. No error message was received on startup. We then received the internal logs as expected, but didn't receive the application log file we were monitoring. We then stopped the forwarder (received the error message again) and waited about 5 minutes. After 5 minutes we started the forwarder and both the splunk internal logs and the monitored log files were continuously coming through. It appears that the stop, pause for a longer time, then start appeared to fix this issue.&lt;/P&gt;

&lt;P&gt;This did not fix the issue where the splunkd logs only came through when the agent was stopped and the monitored logs never came through.&lt;/P&gt;</description>
    <pubDate>Wed, 16 Apr 2014 15:47:42 GMT</pubDate>
    <dc:creator>SarahBOA</dc:creator>
    <dc:date>2014-04-16T15:47:42Z</dc:date>
    <item>
      <title>Why does forwarding stop until i restart splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45466#M8519</link>
      <description>&lt;P&gt;I have a 4.3.3 UF on a windows 2008r2 box that was forwarding windows event logs quite happily. &lt;BR /&gt;
It's now stopped forwarding but, if I restart splunk on the forwarding server, the missing events are forwarded, but no new events until I restart splunk again. &lt;BR /&gt;
Short of restarting splunk every 5 minutes, can any one suggest why this  might be happening?&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2013 14:13:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45466#M8519</guid>
      <dc:creator>capilarity</dc:creator>
      <dc:date>2013-05-24T14:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: Why does forwarding stop until i restart splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45467#M8520</link>
      <description>&lt;P&gt;On the forwarder, have you looked at the splunkd log? You will find it in the subdirectory $SPLUNK_HOME\var\log\splunk&lt;/P&gt;

&lt;P&gt;Let us know what you find there...&lt;/P&gt;</description>
      <pubDate>Fri, 24 May 2013 16:19:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45467#M8520</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2013-05-24T16:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why does forwarding stop until i restart splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45468#M8521</link>
      <description>&lt;P&gt;We are experiencing a few issues with our windows forwarders and one of them sounds like it might be the same. We have this issue where we get splunk internal logs constantly, but monitored files are only sent on shutdown of the universal forwarder. This problem appears to be that the splunk forwarder was trying to "restart" too quickly. When we tried to restart the forwarder we received an error message that the process was taking too long - but it appeared stopped in the windows serverice listing so we started it up again. No error message was received on startup. We then received the internal logs as expected, but didn't receive the application log file we were monitoring. We then stopped the forwarder (received the error message again) and waited about 5 minutes. After 5 minutes we started the forwarder and both the splunk internal logs and the monitored log files were continuously coming through. It appears that the stop, pause for a longer time, then start appeared to fix this issue.&lt;/P&gt;

&lt;P&gt;This did not fix the issue where the splunkd logs only came through when the agent was stopped and the monitored logs never came through.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 15:47:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45468#M8521</guid>
      <dc:creator>SarahBOA</dc:creator>
      <dc:date>2014-04-16T15:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: Why does forwarding stop until i restart splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45469#M8522</link>
      <description>&lt;P&gt;Accepted the answer by mistake - any way you can unaccept?&lt;/P&gt;

&lt;P&gt;The issue went away when we upgraded, we are now splunk 6 and not an issue so far......&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2014 13:24:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45469#M8522</guid>
      <dc:creator>capilarity</dc:creator>
      <dc:date>2014-04-22T13:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why does forwarding stop until i restart splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45470#M8523</link>
      <description>&lt;P&gt;I had the same symptoms, it was a configuration issue.&lt;BR /&gt;
Make sure you fully understand ignoreOlderThan=&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Inputsconf"&gt;https://docs.splunk.com/Documentation/Splunk/6.6.1/Admin/Inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;In my case logs were not written to for 7 + days and then splunk will no longer try to read from that file even when new events appeard in the file..&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 16:08:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45470#M8523</guid>
      <dc:creator>jareddjenkins</dc:creator>
      <dc:date>2017-06-22T16:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why does forwarding stop until i restart splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45471#M8524</link>
      <description>&lt;P&gt;In my case, it was a misunderstanding of ignoreOlderThan= in inputs.conf.&lt;/P&gt;

&lt;P&gt;ignoreOlderThan will completely ignore files that ever reach this threshold.&lt;BR /&gt;
From the inputs.conf documentation.&lt;BR /&gt;
"Do NOT select a time that files you want to read could reach in age, even temporarily"&lt;/P&gt;

&lt;P&gt;My files wouldn't write to the logs for several weeks and then begin writing again. Splunk would not even try to ingest them.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2017 16:11:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-does-forwarding-stop-until-i-restart-splunk/m-p/45471#M8524</guid>
      <dc:creator>jareddjenkins</dc:creator>
      <dc:date>2017-06-22T16:11:44Z</dc:date>
    </item>
  </channel>
</rss>

