<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local udp:514  input not forwarded in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538092#M90200</link>
    <description>&lt;P&gt;Heavy forwarder F2 should be listening on port 9997 for the data from F1.&lt;/P&gt;&lt;P&gt;The use of intermediate forwarders like F2 is discouraged.&amp;nbsp; Forwarders should send data directly to indexers.&amp;nbsp; Having another forwarder in the path can lead to unbalanced data on the indexers, can be a bottleneck, and is an extra layer to manage and troubleshoot.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2021 14:15:52 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-02-01T14:15:52Z</dc:date>
    <item>
      <title>Local udp:514  input not forwarded</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538074#M90191</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;I have 2 heavy forwarders set up; F1 is forwarding to F2, and F2 forwards to splunk cloud.&lt;/P&gt;&lt;P&gt;On F1 i have set up a local input to listening on UDP:514 for events, this works great and forwards to cloud.&lt;BR /&gt;On F2 i have set up a local input for UDP:514 exactly like i did on F1, but no events are forwarded, does anyone here have a clue to what could be wrong?&lt;BR /&gt;&lt;BR /&gt;The events are of the same type, so as long as this works on F1 it should not be an issue with interpreting/reading the events.&lt;/P&gt;&lt;P&gt;I have checked the FW and the events are beeing received, and also after setting UDP processor log level to debug i get this in my splunkd.log on F2:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;02-01-2021 12:54:00.520 +0100 DEBUG UDPInputProcessor - callback()
02-01-2021 12:54:10.512 +0100 DEBUG UDPInputProcessor - callback()
02-01-2021 12:54:18.502 +0100 INFO  TcpOutputProc - Found currently active indexer. Connected to idx=ForwarderIP:30132, reuse=1.
02-01-2021 12:54:20.467 +0100 DEBUG UDPInputProcessor - Generating UDP metrics
02-01-2021 12:54:20.467 +0100 DEBUG UDPInputProcessor - callback()
02-01-2021 12:54:30.514 +0100 DEBUG UDPInputProcessor - callback()
02-01-2021 12:54:34.790 +0100 DEBUG UDPInputProcessor - event=data from="PC100.Local (new)" status=accepted
02-01-2021 12:54:34.790 +0100 DEBUG UDPInputProcessor - UDPInputProcessor::when_events called
02-01-2021 12:54:34.801 +0100 DEBUG UDPInputProcessor - event=data from=PC100.Local status=accepted
02-01-2021 12:54:34.801 +0100 DEBUG UDPInputProcessor - UDPInputProcessor::when_events called
02-01-2021 12:54:34.812 +0100 DEBUG UDPInputProcessor - event=data from=PC100.Local status=accepted
02-01-2021 12:54:34.812 +0100 DEBUG UDPInputProcessor - UDPInputProcessor::when_events called
02-01-2021 12:54:34.830 +0100 DEBUG UDPInputProcessor - event=data from=PC100.Local status=accepted
02-01-2021 12:54:34.831 +0100 DEBUG UDPInputProcessor - UDPInputProcessor::when_events called
02-01-2021 12:54:44.829 +0100 DEBUG UDPInputProcessor - callback()
02-01-2021 12:54:44.829 +0100 DEBUG UDPInputProcessor - event=sendDoneKey source=PC100.Local localport=514
02-01-2021 12:54:44.829 +0100 DEBUG UDPInputProcessor - event=deleteSource source=PC100.Local localport=514
02-01-2021 12:54:48.413 +0100 INFO  TcpOutputProc - Found currently active indexer. Connected to idx=ForwarderIP:30132, reuse=1.
02-01-2021 12:54:50.471 +0100 DEBUG UDPInputProcessor - Generating UDP metrics
02-01-2021 12:54:50.471 +0100 DEBUG UDPInputProcessor - callback()&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have had to replace some hostnames as you probably can see. Hopefully someone here can help me figure this out.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 12:19:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538074#M90191</guid>
      <dc:creator>hethu</dc:creator>
      <dc:date>2021-02-01T12:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Local udp:514  input not forwarded</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538092#M90200</link>
      <description>&lt;P&gt;Heavy forwarder F2 should be listening on port 9997 for the data from F1.&lt;/P&gt;&lt;P&gt;The use of intermediate forwarders like F2 is discouraged.&amp;nbsp; Forwarders should send data directly to indexers.&amp;nbsp; Having another forwarder in the path can lead to unbalanced data on the indexers, can be a bottleneck, and is an extra layer to manage and troubleshoot.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 14:15:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538092#M90200</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-01T14:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: Local udp:514  input not forwarded</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538722#M90266</link>
      <description>&lt;P&gt;It seems the input i set up through the web interface, did not change the active inputs.conf.... after i manually altered this config file, the forwarder correctly received and forwarded my events.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 09:37:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538722#M90266</guid>
      <dc:creator>hethu</dc:creator>
      <dc:date>2021-02-05T09:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Local udp:514  input not forwarded</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538769#M90275</link>
      <description>To help future readers, please describe the manual changes you had to make.</description>
      <pubDate>Fri, 05 Feb 2021 13:58:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Local-udp-514-input-not-forwarded/m-p/538769#M90275</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-02-05T13:58:10Z</dc:date>
    </item>
  </channel>
</rss>

